T08 · Insecure Dependencies
- Location
SKILL.md:50- Finding
Execution of an Unpinned Remote npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 50–51
Vulnerability Type: Supply-chain risk through automatic execution of a mutable dependency
Risk Level: HighVulnerable Code
json "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/chess/mcp"]Technical Analysis
The documented MCP configuration invokes
npxwith the-yoption to automatically download and executemcp-remote@latest. Thelatestnpm tag is mutable and does not identify a fixed, previously audited release. The configuration also provides no package-integrity verification.Consequently, the code executed when the MCP client starts may differ from the code that existed when this Skill was reviewed. A compromised npm package, maintainer account, publication process, or malicious future release could introduce arbitrary executable behavior.
Attack Path
- An attacker compromises the
mcp-remotepackage, an authorized publisher account, or its release pipeline. - The attacker publishes a malicious version and assigns it to the mutable
latesttag. - A user applies the MCP configuration from
SKILL.md. - When the MCP server starts,
npx -yretrieves the package without requiring installation confirmation. - The downloaded package executes locally under the identity and permissions of the user running the Agent or MCP client.
- The malicious package can access resources available to that process, subject to operating-system permissions and any sandbox controls.
Impact Assessment
Successful exploitation permits arbitrary code execution with the privileges of the Agent or MCP-client user. Depending on that account's access and runtime isolation, the malicious dependency could read or modify accessible files, inspect environment variables, access available credentials, initiate network connections, or alter user-level application state. The reviewed material does not establish privilege escalation, persisten ...[truncated 64 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed package version. - Record the dependency in a lockfile that preserves its resolved version and integrity hash.
- Avoid downloading dependencies automatically during MCP startup; install reviewed dependencies through a controlled build or deployment process.
- Where practical, vendor the audited MCP client or use an internally approved package registry.
- Verify package provenance, signatures, and integrity before installation.
- Run the MCP client in a least-privilege sandbox with restricted filesystem, credential, environment-variable, and network access.
- Establish a controlled update process in which new versions are reviewed and tested before deployment.
- Replace
