T08 · Insecure Dependencies
- Location
SKILL.md:48- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 48–52
Vulnerability Type: Supply-chain risk from an unpinned third-party runtime dependency
Risk Level: MediumVulnerable Code
json { "mcpServers": { "pipeworx-cocktails": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/cocktails/mcp"] } } }Technical Analysis
The MCP configuration invokes
npxwith both the automatic-confirmation option (-y) and the mutable package referencemcp-remote@latest. When the configured server starts, npm may download and execute whichever package version thelatesttag resolves to at that time.Because neither an exact package version nor package integrity is pinned, the effective executable can change after the Skill has been reviewed. A malicious release, compromised publisher account, or compromised package-distribution path could therefore introduce arbitrary code without any modification to this repository. The
-yoption further removes the normal interactive confirmation before execution.The documented remote MCP endpoint is consistent with the Skill's stated cocktail-recipe purpose, and the reviewed file contains no evidence that the current package or endpoint is malicious. This finding concerns the unsafe dependency-execution pattern and its supply-chain exposure.
Attack Path
- An attacker compromises the
mcp-remotepublisher account or otherwise causes a malicious release to receive the npmlatesttag. - A user or agent starts the documented MCP configuration.
npx -yresolves and downloads the attacker-controlled package without interactive confirmation.- npm executes the package locally under the identity of the process launching the MCP server.
- The malicious package accesses resources available to that user or process and may execute additional commands.
Impact Assessment
Successful exploitation permits arbitrary code execution with t ...[truncated 420 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith a reviewed, exact version such asmcp-remote@x.y.z. - Manage the dependency through a committed lockfile that records resolved package versions and integrity hashes.
- Install dependencies during a controlled build or deployment phase instead of downloading and executing them dynamically at runtime.
- Remove
-ywhere feasible so unexpected package installation requires explicit approval. - Use a trusted internal registry or allowlisted package mirror and continuously monitor the pinned dependency for security advisories.
- Run the MCP process in a restricted environment with minimal filesystem access, no unnecessary credentials, and constrained network permissions.
- Review and test dependency upgrades before intentionally updating the pinned version.
- Replace
