Back to skill

Security audit

Pipeworx github

Security checks for vulnerabilities and agentic risk

Overview

This GitHub lookup skill is mostly coherent, but it routes queries through a third-party gateway and recommends auto-running an unpinned npm package.

Review this before installing if your GitHub searches, repository names, usernames, or research interests are sensitive. Prefer a pinned mcp-remote version or a vetted local MCP client, and avoid sending private repository identifiers or confidential query terms through the gateway.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:39
Finding

Automatic Execution of an Unpinned npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39-46
Vulnerability Type: Unpinned third-party dependency with automatic remote execution
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-github": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/github/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration invokes npx with both the automatic-confirmation option (-y) and the mutable mcp-remote@latest package reference. When the configuration is used, npx may download and execute whichever package version is designated as latest at that time.

Because the dependency is not pinned to a reviewed version or integrity digest, its effective code can change after this Skill has been audited. The automatic-confirmation option further reduces the opportunity for a user to inspect or reject an unexpected package download.

This creates a supply-chain execution boundary outside the reviewed project. Compromise of the npm package, its maintainer account, or a transitive dependency could result in arbitrary code being executed by the local agent process.

Attack Path

  1. An attacker compromises the mcp-remote npm package publication chain, maintainer account, or a dependency included in a new release.
  2. The attacker publishes malicious code in a version selected by the latest tag.
  3. A user or agent activates the documented MCP configuration.
  4. npx -y mcp-remote@latest downloads the mutable package without an interactive confirmation prompt.
  5. The malicious package executes with the permissions and environment available to the agent process.
  6. Depending on those permissions, the package could access local files, environment variables, network resources, or credentials available to that process.

Impact Assessment

Successful exploitation could provide arbitrary code execution under ...[truncated 382 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed package version.
  • Use a lockfile and verify the package through an approved dependency-review process.
  • Enforce package integrity with a trusted checksum or registry integrity metadata.
  • Prefer a preinstalled and vetted local binary rather than downloading executable code when the Skill is invoked.
  • Remove -y where practical so unexpected installation or version changes require explicit confirmation.
  • Run the MCP client in a restricted environment with minimal filesystem, credential, and network access.
  • Monitor the pinned package and its transitive dependencies for advisories before performing controlled upgrades.

other

Note
Location
SKILL.md:28
Finding

GitHub Query Data Is Routed Through an Undisclosed Third-Party Gateway

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 3 and 28-45
Vulnerability Type: Third-party data disclosure
Risk Level: Low

Vulnerable Code

yaml
description: Search GitHub repos, view issues, and look up user profiles via the public REST API — no token required
bash
curl -s -X POST https://gateway.pipeworx.io/github/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_repos","arguments":{"query":"react hooks","sort":"stars","limit":5}}}'
json
{
  "mcpServers": {
    "pipeworx-github": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/github/mcp"]
    }
  }
}

Technical Analysis

Although the Skill describes its functionality as using GitHub's public REST API, its documented requests are sent to gateway.pipeworx.io rather than directly to GitHub's official API endpoint. This intermediary can observe request content and associated connection metadata.

Data exposed to the gateway may include search terms, repository owner and name combinations, issue queries, queried usernames, IP-derived metadata, timestamps, and general usage patterns. The documentation does not clearly explain this trust boundary or provide data-retention and privacy information.

No authentication token or other secret is included in the reviewed example, so the finding does not demonstrate credential theft. The risk concerns disclosure and correlation of query data through an external service.

Attack Path

  1. A user submits a repository search, issue request, or profile lookup through the Skill.
  2. The query is transmitted to https://gateway.pipeworx.io/github/mcp.
  3. The third-party gateway receives the request before obtaining or returning GitHub data.
  4. The gateway operator, or an attacker who compromises the gateway, can observe and potentially reta ...[truncated 602 chars]
Remediation
View remediation

Remediation Suggestions

  • Send requests directly to GitHub's official REST API when an intermediary is unnecessary.
  • Clearly disclose that requests are processed by gateway.pipeworx.io, including the categories of data exposed to it.
  • Document the gateway operator's privacy policy, retention period, logging behavior, and security controls.
  • Obtain explicit user approval before transmitting potentially sensitive repository names, usernames, or search terms.
  • Minimize request metadata and avoid sending secrets, private repository identifiers, or confidential query content.
  • Validate gateway responses and use appropriate TLS and endpoint restrictions.
  • Provide a direct GitHub API configuration as a privacy-preserving alternative.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "🐙"
    homepage: https://pipeworx.io/packs/github
---

Static analysis

No suspicious patterns detected.