Back to skill

Security audit

Pipeworx catfacts

Security checks for vulnerabilities and agentic risk

Overview

The cat-facts skill is mostly straightforward, but its setup runs an unpinned npm package automatically, which creates a supply-chain review concern.

Review the MCP setup before installing. Prefer a pinned mcp-remote version or a locked dependency, and run it with limited local permissions. The cat-facts functionality itself appears narrow and harmless, but the automatic unpinned npm execution is the part that needs caution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Unpinned Third-Party Package Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–48
Vulnerability Type: Unsafe execution of an unpinned third-party dependency
Risk Level: Medium

Complete Code Snippet:

json
{
  "mcpServers": {
    "pipeworx-catfacts": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/catfacts/mcp"]
    }
  }
}

Technical Analysis

The documented MCP configuration invokes npx -y to download and execute mcp-remote@latest. The latest npm tag is mutable and does not identify a specific reviewed artifact. The -y option suppresses the normal confirmation prompt, allowing the selected package version to execute automatically.

Consequently, the code executed on a future invocation can differ from the code available when this skill was audited. A malicious release, compromised package, or compromised maintainer account could turn this configuration into a supply-chain code-execution channel.

Attack Path

  1. An attacker compromises the npm package, its maintainer account, or the publication process.
  2. The attacker publishes a malicious release and causes mcp-remote@latest to resolve to it.
  3. A user enables or launches the MCP configuration from SKILL.md.
  4. npx -y retrieves the attacker-controlled package without an interactive confirmation prompt.
  5. The package executes locally with the privileges and environment of the process that launched the agent or MCP server.
  6. The malicious package can perform actions permitted to that local account, such as reading accessible files or environment variables, executing subprocesses, and initiating network requests.

Impact Assessment

Successful exploitation provides arbitrary code execution with the privileges of the invoking user or agent process. The accessible scope may include local files, environment variables, agent data, available credentials, subprocess execution, and outb ...[truncated 233 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed version, such as mcp-remote@x.y.z.
  • Install the dependency through a controlled package manifest and lockfile rather than downloading it dynamically during startup.
  • Verify the resolved package with an integrity hash and retain the reviewed artifact in a trusted registry or cache.
  • Remove runtime use of npx -y so package acquisition and execution do not occur silently.
  • Review package updates before changing the pinned version, including maintainership, published contents, transitive dependencies, and security advisories.
  • Run the MCP bridge with least privilege in a sandbox or restricted account, exposing only the files, environment variables, and network destinations required for the cat-facts service.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "🐱"
    homepage: https://pipeworx.io/packs/catfacts
---

Static analysis

No suspicious patterns detected.