T08 · Insecure Dependencies
- Location
SKILL.md:55- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55–61
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: Mediumjson { "mcpServers": { "pipeworx-citybikes": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/citybikes/mcp"] } } }Technical Analysis
The documented setup uses
npx -yto download and executemcp-remote@latest. Thelatestnpm tag is mutable, so the package code executed in the future may differ from the version available when this skill was audited. The-yoption suppresses the installation confirmation, allowing the retrieved package to run automatically.No exact version, package integrity hash, lockfile, or equivalent verification mechanism is specified. Consequently, the effective executable dependency is controlled by the current state of the external npm registry and package publisher account rather than by immutable, locally reviewed project content.
This is a supply-chain weakness. It does not prove that the current
mcp-remotepackage is malicious, but a compromised publisher account, malicious future release, or compromised dependency could turn the documented setup into an arbitrary-code-execution path.Attack Path
- An attacker compromises the
mcp-remotenpm publisher account, its release process, or a dependency included in a future release. - The attacker publishes malicious code under the version referenced by the mutable
latesttag. - A user applies the documented MCP configuration and starts the configured server.
npx -yretrieves the attacker-controlled package without requesting installation confirmation.- Node.js executes the downloaded package with the privileges and environment of the user running the Agent.
- The malicious package can access resources available to that process and perform unauthorized actions within those permission boundaries.
Impact Assessment
Successful ...[truncated 764 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version, such asmcp-remote@x.y.z; do not use a mutable npm tag or a version range. - Install the dependency through a committed package manifest and lockfile so that transitive dependency versions are reproducible.
- Verify package integrity using the lockfile's integrity metadata and a trusted registry. For higher-assurance deployments, record and validate an independently obtained package digest.
- Remove
-ywhere interactive use permits so users are not silently authorizing newly downloaded executable code. - Prefer a preinstalled, locally reviewed dependency over downloading executable code when the MCP server starts.
- Review package provenance, publisher identity, release history, lifecycle scripts, and transitive dependencies before approving a version.
- Run the MCP bridge with least privilege in a sandbox or container that restricts filesystem access, environment variables, subprocess execution, and outbound network access.
- Establish a controlled update process in which dependency upgrades are reviewed and tested before the pinned version is changed.
- Replace
