Back to skill

Security audit

Pipeworx carbon

Security checks for vulnerabilities and agentic risk

Overview

The skill's carbon-data purpose is coherent, but its setup runs an unpinned npm package through npx, which creates a review-worthy supply-chain risk.

Review this before installing. The data tools themselves look narrowly scoped, but you should pin `mcp-remote` to a trusted exact version or install it through a controlled process, and be aware that requests go through Pipeworx's gateway rather than directly to the public Carbon Intensity API.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:59
Finding

Unpinned npm Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 59–65
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

json
{
  "mcpServers": {
    "pipeworx-carbon": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/carbon/mcp"]
    }
  }
}

Technical Analysis

The configuration invokes npx with both the automatic-confirmation option (-y) and the mutable latest package tag. Consequently, setup can download and execute whichever mcp-remote release is identified as latest at that moment, rather than the specific release reviewed with this Skill.

This creates a supply-chain trust boundary outside the audited project. A future malicious release, compromised npm publisher account, or compromised upstream package could introduce arbitrary lifecycle or runtime code. The -y option removes the interactive installation confirmation that might otherwise alert the user to package retrieval.

The configuration also connects the package to https://gateway.pipeworx.io/carbon/mcp. Although that intermediary is disclosed in the file and no sensitive input is requested, it should be documented as a third-party gateway rather than represented solely as direct use of the official Carbon Intensity API.

Attack Path

  1. An attacker compromises the npm publisher account, upstream release process, or another relevant package-distribution component for mcp-remote.
  2. The attacker publishes a malicious release that becomes the version resolved by the latest tag.
  3. A user applies the documented MCP setup configuration.
  4. npx -y downloads the unpinned release without requesting interactive confirmation.
  5. npm lifecycle logic or package runtime code executes locally under the account running the MCP server.
  6. The malicious package can perform actions available to that account, such as reading accessible files, making network requests ...[truncated 578 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an explicitly audited, exact package version; do not use a mutable tag or a version range.
  • Use a lockfile and verify the package integrity hash against a trusted, reviewed artifact.
  • Validate the npm package name, publisher identity, source repository, release provenance, and maintenance history before deployment.
  • Prefer a locally installed, reviewed dependency over automatic package retrieval during each launch.
  • Disable npm lifecycle scripts where they are not required, such as by installing with --ignore-scripts, after verifying that doing so is compatible with the package.
  • Execute the MCP process under a dedicated least-privileged account or sandbox with restricted filesystem, environment-variable, subprocess, and network access.
  • Maintain a controlled dependency-update process in which new versions are reviewed and tested before the pinned version is changed.
  • Clearly document that requests pass through the Pipeworx gateway, and consider connecting directly to the official Carbon Intensity API when the intermediary is unnecessary.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Example

bash
curl -s -X POST https://gateway.pipeworx.io/carbon/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"get_generation_mix","arguments":{}}}'

Static analysis

No suspicious patterns detected.