T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Automatic Execution of an Unpinned npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 54-61
Vulnerability Type: Supply-chain risk caused by an unpinned, automatically downloaded dependency
Risk Level: HighVulnerable Code Snippet:
json { "mcpServers": { "pipeworx-dicebear": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/dicebear/mcp"] } } }Technical Analysis
The recommended MCP configuration invokes
npxwith the-yoption and executesmcp-remote@latest. Thelatestnpm distribution tag is mutable and does not identify a fixed, previously audited package version. The-yoption suppresses the normal installation confirmation, causing the dependency to be downloaded and executed automatically.Consequently, the code executed when this configuration is used may differ from the code available when the skill was audited. The configuration provides no exact version pin, package integrity hash, lockfile, provenance validation, or other mechanism for detecting an altered package release.
This creates a supply-chain execution channel. Exploitation would require compromise or malicious modification of the referenced npm package, its maintainer account, the package distribution process, or another relevant dependency-resolution component.
Attack Path
- An attacker compromises the
mcp-remotenpm package, its maintainer account, or the release process associated with the mutablelatesttag. - The attacker publishes a malicious version and assigns or causes the
latesttag to resolve to it. - A user or agent activates the documented MCP configuration.
npx -ydownloads the package without interactive confirmation.- The downloaded package executes locally under the privileges and environment of the invoking user or agent.
- Malicious package code can access resources available to that process.
Impact Assessment
Successful ...[truncated 567 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version such asmcp-remote@x.y.z. - Use a lockfile and verify the resolved package and transitive dependency versions.
- Validate package integrity using trusted registry integrity metadata or a separately maintained cryptographic hash.
- Remove
-ywhere practical so that unexpected installation or version changes require explicit approval. - Prefer a preinstalled, reviewed dependency rather than downloading executable code when the skill is activated.
- Document the official package source, expected publisher, reviewed version, and upgrade procedure.
- Run the MCP process in a sandbox with minimal filesystem, network, credential, and environment-variable access.
- Review and pin transitive dependencies before updating the approved version.
- Replace
