T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Execution of an Unreviewed Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20-30
Vulnerability Type: Third-party supply-chain exposure through directnpxexecution
Risk Level: MediumVulnerable Code
markdown ## Setup ```bash claude mcp add shrimp -- npx @hermitsh/shrimp-mcp@1.0.6That's it. To upgrade to phone sync later:
bash npx @hermitsh/shrimp-mcp@1.0.6 pairtext ### Technical Analysis The installation and pairing instructions use `npx` to retrieve and execute `@hermitsh/shrimp-mcp@1.0.6` from the configured npm registry. The executable package and its source code are not included in the audited project, so its lifecycle scripts, runtime behavior, transitive dependencies, network operations, and filesystem access cannot be verified from this repository. Pinning the package to version `1.0.6` reduces unintended version drift, but it does not independently verify the package's integrity or provenance. A compromised publisher account, package release, dependency, registry, or local registry configuration could cause external code to execute with the invoking user's privileges. The documented package capabilities include reading and modifying local task data, optional cloud synchronization, feedback submission, prompt and provider configuration access, activity-log access, and inbox access. These capabilities increase the potential impact if the downloaded package or one of its dependencies is compromised. This finding does not establish that the named package is malicious. It identifies an unverified supply-chain execution boundary that cannot be fully audited because the executable implementation is absent from the project. ### Attack Path 1. An attacker compromises the npm publisher, a transitive dependency, the package distribution channel, or the registry configured on the victim's system. 2. The victim follows the documented setup or pairing instructions. 3. `npx` retrieves the external package and resolves any required dependencies. 4. ...[truncated 1285 chars]- Remediation
View remediation
Remediation Suggestions
- Vendor the exact executable source and dependency metadata into a reviewable release process, or provide a link to reproducible source corresponding to version
1.0.6. - Publish and verify cryptographic integrity information for the package artifact. Use a lockfile with integrity hashes for all transitive dependencies.
- Prefer a controlled installation step over implicit download-and-execute behavior. Document how users can inspect the package before execution.
- Run installation with lifecycle scripts disabled where compatible, such as by using npm's
--ignore-scriptsoption, and explicitly document any scripts that are genuinely required. - Document the expected npm registry and advise users to verify their registry configuration before installation.
- Publish package provenance or signed release attestations and verify them in the installation process.
- Document all expected network endpoints, telemetry behavior, files accessed, and data transmitted by local and paired modes.
- Run the MCP server with least privilege, restricting filesystem access to required storage paths and limiting network access to documented endpoints.
- Separate sensitive paired-mode capabilities from basic local task management and require explicit user authorization before enabling prompt, provider, inbox, or cloud-sync access.
- Provide uninstall, data-removal, pairing-revocation, and incident-response instructions.
- Vendor the exact executable source and dependency metadata into a reviewable release process, or provide a link to reproducible source corresponding to version
