T08 · Insecure Dependencies
- Location
SKILL.md:43- Finding
Unpinned Third-Party Package Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–48
Vulnerability Type: Unsafe execution of an unpinned third-party dependency
Risk Level: MediumComplete Code Snippet:
json { "mcpServers": { "pipeworx-catfacts": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/catfacts/mcp"] } } }Technical Analysis
The documented MCP configuration invokes
npx -yto download and executemcp-remote@latest. Thelatestnpm tag is mutable and does not identify a specific reviewed artifact. The-yoption suppresses the normal confirmation prompt, allowing the selected package version to execute automatically.Consequently, the code executed on a future invocation can differ from the code available when this skill was audited. A malicious release, compromised package, or compromised maintainer account could turn this configuration into a supply-chain code-execution channel.
Attack Path
- An attacker compromises the npm package, its maintainer account, or the publication process.
- The attacker publishes a malicious release and causes
mcp-remote@latestto resolve to it. - A user enables or launches the MCP configuration from
SKILL.md. npx -yretrieves the attacker-controlled package without an interactive confirmation prompt.- The package executes locally with the privileges and environment of the process that launched the agent or MCP server.
- The malicious package can perform actions permitted to that local account, such as reading accessible files or environment variables, executing subprocesses, and initiating network requests.
Impact Assessment
Successful exploitation provides arbitrary code execution with the privileges of the invoking user or agent process. The accessible scope may include local files, environment variables, agent data, available credentials, subprocess execution, and outb ...[truncated 233 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version, such asmcp-remote@x.y.z. - Install the dependency through a controlled package manifest and lockfile rather than downloading it dynamically during startup.
- Verify the resolved package with an integrity hash and retain the reviewed artifact in a trusted registry or cache.
- Remove runtime use of
npx -yso package acquisition and execution do not occur silently. - Review package updates before changing the pinned version, including maintainership, published contents, transitive dependencies, and security advisories.
- Run the MCP bridge with least privilege in a sandbox or restricted account, exposing only the files, environment variables, and network destinations required for the cat-facts service.
- Replace
