Back to skill

Security audit

Pipeworx cocktails

Security checks for vulnerabilities and agentic risk

Overview

The cocktail-recipe skill is coherent, but its setup automatically runs an unpinned npm package, so users should review that risk before installing.

Install only if you are comfortable with the MCP config running npm code through npx. Prefer pinning mcp-remote to a reviewed exact version, running it in a restricted environment, and avoiding unnecessary secrets in the agent environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:48
Finding

Unpinned npm Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48–52
Vulnerability Type: Supply-chain risk from an unpinned third-party runtime dependency
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-cocktails": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/cocktails/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration invokes npx with both the automatic-confirmation option (-y) and the mutable package reference mcp-remote@latest. When the configured server starts, npm may download and execute whichever package version the latest tag resolves to at that time.

Because neither an exact package version nor package integrity is pinned, the effective executable can change after the Skill has been reviewed. A malicious release, compromised publisher account, or compromised package-distribution path could therefore introduce arbitrary code without any modification to this repository. The -y option further removes the normal interactive confirmation before execution.

The documented remote MCP endpoint is consistent with the Skill's stated cocktail-recipe purpose, and the reviewed file contains no evidence that the current package or endpoint is malicious. This finding concerns the unsafe dependency-execution pattern and its supply-chain exposure.

Attack Path

  1. An attacker compromises the mcp-remote publisher account or otherwise causes a malicious release to receive the npm latest tag.
  2. A user or agent starts the documented MCP configuration.
  3. npx -y resolves and downloads the attacker-controlled package without interactive confirmation.
  4. npm executes the package locally under the identity of the process launching the MCP server.
  5. The malicious package accesses resources available to that user or process and may execute additional commands.

Impact Assessment

Successful exploitation permits arbitrary code execution with t ...[truncated 420 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with a reviewed, exact version such as mcp-remote@x.y.z.
  • Manage the dependency through a committed lockfile that records resolved package versions and integrity hashes.
  • Install dependencies during a controlled build or deployment phase instead of downloading and executing them dynamically at runtime.
  • Remove -y where feasible so unexpected package installation requires explicit approval.
  • Use a trusted internal registry or allowlisted package mirror and continuously monitor the pinned dependency for security advisories.
  • Run the MCP process in a restricted environment with minimal filesystem access, no unnecessary credentials, and constrained network permissions.
  • Review and test dependency upgrades before intentionally updating the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

Example: what can I make with rum?

bash
curl -s -X POST https://gateway.pipeworx.io/cocktails/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"cocktails_by_ingredient","arguments":{"ingredient":"rum"}}}'

Static analysis

No suspicious patterns detected.