Back to skill

Security audit

Pipeworx chess

Security checks for vulnerabilities and agentic risk

Overview

The skill is narrowly about public Chess.com data, but its setup runs an unpinned remote npm package automatically, which users should review before installing.

Install only if you are comfortable with a remote MCP gateway and with npx downloading mcp-remote at runtime. Prefer pinning mcp-remote to a reviewed version and running the MCP client with least-privilege access to local files, environment variables, and credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:50
Finding

Execution of an Unpinned Remote npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 50–51
Vulnerability Type: Supply-chain risk through automatic execution of a mutable dependency
Risk Level: High

Vulnerable Code

json
"command": "npx",
"args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/chess/mcp"]

Technical Analysis

The documented MCP configuration invokes npx with the -y option to automatically download and execute mcp-remote@latest. The latest npm tag is mutable and does not identify a fixed, previously audited release. The configuration also provides no package-integrity verification.

Consequently, the code executed when the MCP client starts may differ from the code that existed when this Skill was reviewed. A compromised npm package, maintainer account, publication process, or malicious future release could introduce arbitrary executable behavior.

Attack Path

  1. An attacker compromises the mcp-remote package, an authorized publisher account, or its release pipeline.
  2. The attacker publishes a malicious version and assigns it to the mutable latest tag.
  3. A user applies the MCP configuration from SKILL.md.
  4. When the MCP server starts, npx -y retrieves the package without requiring installation confirmation.
  5. The downloaded package executes locally under the identity and permissions of the user running the Agent or MCP client.
  6. The malicious package can access resources available to that process, subject to operating-system permissions and any sandbox controls.

Impact Assessment

Successful exploitation permits arbitrary code execution with the privileges of the Agent or MCP-client user. Depending on that account's access and runtime isolation, the malicious dependency could read or modify accessible files, inspect environment variables, access available credentials, initiate network connections, or alter user-level application state. The reviewed material does not establish privilege escalation, persisten ...[truncated 64 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed package version.
  • Record the dependency in a lockfile that preserves its resolved version and integrity hash.
  • Avoid downloading dependencies automatically during MCP startup; install reviewed dependencies through a controlled build or deployment process.
  • Where practical, vendor the audited MCP client or use an internally approved package registry.
  • Verify package provenance, signatures, and integrity before installation.
  • Run the MCP client in a least-privilege sandbox with restricted filesystem, credential, environment-variable, and network access.
  • Establish a controlled update process in which new versions are reviewed and tested before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

Example: Hikaru's blitz stats

bash
curl -s -X POST https://gateway.pipeworx.io/chess/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"get_stats","arguments":{"username":"hikaru"}}}'

Static analysis

No suspicious patterns detected.