T08 · Insecure Dependencies
- Location
SKILL.md:59- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 59–65
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumjson { "mcpServers": { "pipeworx-carbon": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/carbon/mcp"] } } }Technical Analysis
The configuration invokes
npxwith both the automatic-confirmation option (-y) and the mutablelatestpackage tag. Consequently, setup can download and execute whichevermcp-remoterelease is identified as latest at that moment, rather than the specific release reviewed with this Skill.This creates a supply-chain trust boundary outside the audited project. A future malicious release, compromised npm publisher account, or compromised upstream package could introduce arbitrary lifecycle or runtime code. The
-yoption removes the interactive installation confirmation that might otherwise alert the user to package retrieval.The configuration also connects the package to
https://gateway.pipeworx.io/carbon/mcp. Although that intermediary is disclosed in the file and no sensitive input is requested, it should be documented as a third-party gateway rather than represented solely as direct use of the official Carbon Intensity API.Attack Path
- An attacker compromises the npm publisher account, upstream release process, or another relevant package-distribution component for
mcp-remote. - The attacker publishes a malicious release that becomes the version resolved by the
latesttag. - A user applies the documented MCP setup configuration.
npx -ydownloads the unpinned release without requesting interactive confirmation.- npm lifecycle logic or package runtime code executes locally under the account running the MCP server.
- The malicious package can perform actions available to that account, such as reading accessible files, making network requests ...[truncated 578 chars]
- An attacker compromises the npm publisher account, upstream release process, or another relevant package-distribution component for
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an explicitly audited, exact package version; do not use a mutable tag or a version range. - Use a lockfile and verify the package integrity hash against a trusted, reviewed artifact.
- Validate the npm package name, publisher identity, source repository, release provenance, and maintenance history before deployment.
- Prefer a locally installed, reviewed dependency over automatic package retrieval during each launch.
- Disable npm lifecycle scripts where they are not required, such as by installing with
--ignore-scripts, after verifying that doing so is compatible with the package. - Execute the MCP process under a dedicated least-privileged account or sandbox with restricted filesystem, environment-variable, subprocess, and network access.
- Maintain a controlled dependency-update process in which new versions are reviewed and tested before the pinned version is changed.
- Clearly document that requests pass through the Pipeworx gateway, and consider connecting directly to the official Carbon Intensity API when the intermediary is unnecessary.
- Replace
