T08 · Insecure Dependencies
- Location
SKILL.md:49- Finding
Unpinned Remote Package Execution Through MCP Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 49–53
Vulnerability Type: Insecure third-party dependency execution
Risk Level: HighVulnerable Code
json { "mcpServers": { "pipeworx-chucknorris": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/chucknorris/mcp"] } } }Technical Analysis
The MCP configuration instructs the host to execute
npxwith the automatic-confirmation option (-y) and the mutable package referencemcp-remote@latest. This causes package code to be downloaded from a third-party package registry and executed without pinning an audited version or verifying its integrity.Because the
latesttag can resolve to different code after the Skill has been reviewed, the effective executable payload is not stable. Compromise of the package publisher, registry distribution path, or a future malicious package release could turn normal Skill setup into arbitrary code execution. The MCP bridge also connects tohttps://gateway.pipeworx.io/chucknorris/mcp, placing tool discovery and execution behavior behind a third-party service.Attack Path
- An attacker compromises the
mcp-remotepackage publisher, registry account, or distribution channel, or causes the mutablelatesttag to resolve to a malicious release. - A user applies the documented MCP configuration.
- The host runs
npx -y mcp-remote@latest, automatically downloading the currently resolved package without interactive approval. - The downloaded package executes under the privileges and environment of the agent host.
- Malicious code can access resources available to that process, subject to operating-system permissions and any sandboxing in place.
- Separately, compromise of the configured MCP gateway could alter remote tool behavior, return deceptive results, or observe data submitted through tool calls.
Impact Assessme
...[truncated 704 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, audited version rather than a mutable distribution tag. - Use a lockfile and verify the package with a trusted integrity hash or signature before execution.
- Avoid automatic installation and execution through
npx -yin production configurations. Install reviewed dependencies through a controlled deployment process. - Monitor the pinned package and its transitive dependencies for security advisories, publisher changes, and unexpected release behavior.
- Run the MCP bridge with least privilege in a sandbox or container that restricts filesystem access, environment-variable access, process creation, and outbound network connectivity.
- Permit network access only to explicitly required endpoints and document that tool requests pass through a third-party gateway.
- Where practical, use a reviewed local integration or direct access to the official upstream API instead of executing a dynamically retrieved bridge package.
- Authenticate and verify the MCP endpoint where supported, and apply an allowlist for expected tools and response schemas.
- Replace
