T08 · Insecure Dependencies
- Location
SKILL.md:39- Finding
Automatic Execution of an Unpinned npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39-46
Vulnerability Type: Unpinned third-party dependency with automatic remote execution
Risk Level: MediumVulnerable Code
json { "mcpServers": { "pipeworx-github": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/github/mcp"] } } }Technical Analysis
The MCP configuration invokes
npxwith both the automatic-confirmation option (-y) and the mutablemcp-remote@latestpackage reference. When the configuration is used,npxmay download and execute whichever package version is designated as latest at that time.Because the dependency is not pinned to a reviewed version or integrity digest, its effective code can change after this Skill has been audited. The automatic-confirmation option further reduces the opportunity for a user to inspect or reject an unexpected package download.
This creates a supply-chain execution boundary outside the reviewed project. Compromise of the npm package, its maintainer account, or a transitive dependency could result in arbitrary code being executed by the local agent process.
Attack Path
- An attacker compromises the
mcp-remotenpm package publication chain, maintainer account, or a dependency included in a new release. - The attacker publishes malicious code in a version selected by the
latesttag. - A user or agent activates the documented MCP configuration.
npx -y mcp-remote@latestdownloads the mutable package without an interactive confirmation prompt.- The malicious package executes with the permissions and environment available to the agent process.
- Depending on those permissions, the package could access local files, environment variables, network resources, or credentials available to that process.
Impact Assessment
Successful exploitation could provide arbitrary code execution under ...[truncated 382 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed package version. - Use a lockfile and verify the package through an approved dependency-review process.
- Enforce package integrity with a trusted checksum or registry integrity metadata.
- Prefer a preinstalled and vetted local binary rather than downloading executable code when the Skill is invoked.
- Remove
-ywhere practical so unexpected installation or version changes require explicit confirmation. - Run the MCP client in a restricted environment with minimal filesystem, credential, and network access.
- Monitor the pinned package and its transitive dependencies for advisories before performing controlled upgrades.
- Replace
