Back to skill

Security audit

Pipeworx chucknorris

Security checks for vulnerabilities and agentic risk

Overview

The joke skill is simple, but its setup asks users to run an unpinned remote MCP bridge package, which deserves review before installation.

Review this before installing. Prefer a pinned, reviewed MCP bridge version or a sandboxed setup with limited filesystem, environment-variable, and network access. Avoid the `explicit` category unless you intentionally want potentially adult or offensive jokes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:49
Finding

Unpinned Remote Package Execution Through MCP Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 49–53
Vulnerability Type: Insecure third-party dependency execution
Risk Level: High

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-chucknorris": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/chucknorris/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration instructs the host to execute npx with the automatic-confirmation option (-y) and the mutable package reference mcp-remote@latest. This causes package code to be downloaded from a third-party package registry and executed without pinning an audited version or verifying its integrity.

Because the latest tag can resolve to different code after the Skill has been reviewed, the effective executable payload is not stable. Compromise of the package publisher, registry distribution path, or a future malicious package release could turn normal Skill setup into arbitrary code execution. The MCP bridge also connects to https://gateway.pipeworx.io/chucknorris/mcp, placing tool discovery and execution behavior behind a third-party service.

Attack Path

  1. An attacker compromises the mcp-remote package publisher, registry account, or distribution channel, or causes the mutable latest tag to resolve to a malicious release.
  2. A user applies the documented MCP configuration.
  3. The host runs npx -y mcp-remote@latest, automatically downloading the currently resolved package without interactive approval.
  4. The downloaded package executes under the privileges and environment of the agent host.
  5. Malicious code can access resources available to that process, subject to operating-system permissions and any sandboxing in place.
  6. Separately, compromise of the configured MCP gateway could alter remote tool behavior, return deceptive results, or observe data submitted through tool calls.

Impact Assessme

...[truncated 704 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace mcp-remote@latest with an exact, audited version rather than a mutable distribution tag.
  2. Use a lockfile and verify the package with a trusted integrity hash or signature before execution.
  3. Avoid automatic installation and execution through npx -y in production configurations. Install reviewed dependencies through a controlled deployment process.
  4. Monitor the pinned package and its transitive dependencies for security advisories, publisher changes, and unexpected release behavior.
  5. Run the MCP bridge with least privilege in a sandbox or container that restricts filesystem access, environment-variable access, process creation, and outbound network connectivity.
  6. Permit network access only to explicitly required endpoints and document that tool requests pass through a third-party gateway.
  7. Where practical, use a reviewed local integration or direct access to the official upstream API instead of executing a dynamically retrieved bridge package.
  8. Authenticate and verify the MCP endpoint where supported, and apply an allowlist for expected tools and response schemas.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "👊"
    homepage: https://pipeworx.io/packs/chucknorris
---

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file lists an "explicit" category among available joke categories, but it does not provide any user-facing warning that selecting that category may return adult or offensive content. For a user-facing skill description, this is a missing disclosure about content that could affect user safety expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.