Back to skill

Security audit

Pipeworx citybikes

Security checks for vulnerabilities and agentic risk

Overview

The skill’s bike-share data purpose is coherent, but its setup asks users to run an unpinned npm package automatically, which creates a review-worthy supply-chain risk.

Install only if you are comfortable running the MCP bridge with your local user privileges. Prefer pinning mcp-remote to a reviewed version, using a lockfile or controlled install process, and running it with limited filesystem, environment-variable, and network access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:55
Finding

Unpinned npm Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 55–61
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: Medium

json
{
  "mcpServers": {
    "pipeworx-citybikes": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/citybikes/mcp"]
    }
  }
}

Technical Analysis

The documented setup uses npx -y to download and execute mcp-remote@latest. The latest npm tag is mutable, so the package code executed in the future may differ from the version available when this skill was audited. The -y option suppresses the installation confirmation, allowing the retrieved package to run automatically.

No exact version, package integrity hash, lockfile, or equivalent verification mechanism is specified. Consequently, the effective executable dependency is controlled by the current state of the external npm registry and package publisher account rather than by immutable, locally reviewed project content.

This is a supply-chain weakness. It does not prove that the current mcp-remote package is malicious, but a compromised publisher account, malicious future release, or compromised dependency could turn the documented setup into an arbitrary-code-execution path.

Attack Path

  1. An attacker compromises the mcp-remote npm publisher account, its release process, or a dependency included in a future release.
  2. The attacker publishes malicious code under the version referenced by the mutable latest tag.
  3. A user applies the documented MCP configuration and starts the configured server.
  4. npx -y retrieves the attacker-controlled package without requesting installation confirmation.
  5. Node.js executes the downloaded package with the privileges and environment of the user running the Agent.
  6. The malicious package can access resources available to that process and perform unauthorized actions within those permission boundaries.

Impact Assessment

Successful ...[truncated 764 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace mcp-remote@latest with an exact, reviewed version, such as mcp-remote@x.y.z; do not use a mutable npm tag or a version range.
  2. Install the dependency through a committed package manifest and lockfile so that transitive dependency versions are reproducible.
  3. Verify package integrity using the lockfile's integrity metadata and a trusted registry. For higher-assurance deployments, record and validate an independently obtained package digest.
  4. Remove -y where interactive use permits so users are not silently authorizing newly downloaded executable code.
  5. Prefer a preinstalled, locally reviewed dependency over downloading executable code when the MCP server starts.
  6. Review package provenance, publisher identity, release history, lifecycle scripts, and transitive dependencies before approving a version.
  7. Run the MCP bridge with least privilege in a sandbox or container that restricts filesystem access, environment variables, subprocess execution, and outbound network access.
  8. Establish a controlled update process in which dependency upgrades are reviewed and tested before the pinned version is changed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Example: Citi Bike NYC station availability

bash
curl -s -X POST https://gateway.pipeworx.io/citybikes/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"get_network","arguments":{"id":"citi-bike-nyc"}}}'

Static analysis

No suspicious patterns detected.