Back to skill

Security audit

Pipeworx dns

Security checks for vulnerabilities and agentic risk

Overview

This DNS lookup skill is mostly coherent, but its setup runs an unpinned npm package and its DNS queries go through a Pipeworx gateway that is not clearly disclosed in the main description.

Review before installing. Avoid using this skill for private hostnames, internal IPs, incident-response targets, or confidential customer domains unless you are comfortable sending those lookup targets to Pipeworx. Prefer a pinned mcp-remote version or a locally reviewed setup before enabling the MCP configuration.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:43
Finding

Automatic Execution of an Unpinned npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43-49
Vulnerability Type: Supply-chain risk caused by a mutable dependency version
Risk Level: High

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-dns": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/dns/mcp"]
    }
  }
}

Technical Analysis

The setup configuration invokes npx with both the automatic-confirmation option (-y) and the mutable version selector mcp-remote@latest. Consequently, setup can download and execute a dependency release that did not exist when the Skill was audited.

The package is not pinned to an exact audited version, and the configuration provides no lockfile or integrity hash with which to verify the downloaded artifact. If the npm package, maintainer account, publishing pipeline, or dependency chain is compromised, a malicious release selected by latest can execute locally without an additional confirmation prompt.

This is a supply-chain weakness rather than evidence that the currently published package is malicious.

Attack Path

  1. An attacker compromises the mcp-remote package, its maintainer account, its publishing infrastructure, or a transitive dependency.
  2. The attacker publishes a malicious version that becomes the package's latest release.
  3. A user applies the documented MCP configuration.
  4. npx -y resolves and downloads the attacker-controlled release without interactive confirmation.
  5. The downloaded package executes under the identity and environment of the user running the Agent.
  6. Malicious package code can access resources available to that user and initiate additional network or process activity.

Impact Assessment

Successful exploitation would provide code execution with the privileges of the Agent user. The potential scope includes readable or writable files belonging to that account, environm ...[truncated 275 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed version, such as mcp-remote@<audited-version>.
  • Use a lockfile and package-manager integrity metadata to make dependency resolution reproducible.
  • Avoid automatic execution of newly downloaded packages during setup. Install and review the dependency separately before invocation.
  • Monitor the pinned package and its transitive dependencies for security advisories.
  • Run the MCP client with least privilege in a sandbox or container, with restricted filesystem, credential, process, and network access.
  • Require explicit review and testing before updating the pinned version.

other

Warning
Location
SKILL.md:33
Finding

DNS Query Data Is Disclosed to an Inadequately Documented Third-Party Intermediary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 3 and 33-38; the same intermediary is configured at lines 43-49
Vulnerability Type: Third-party data disclosure and unclear trust boundary
Risk Level: Medium

Vulnerable Code

The Skill describes the service as DNS lookups through Google DNS-over-HTTPS:

yaml
description: DNS record lookups via Google DNS-over-HTTPS — A, AAAA, MX, NS, TXT, CNAME, and reverse DNS

However, the documented request sends lookup data to a Pipeworx-controlled gateway:

bash
curl -s -X POST https://gateway.pipeworx.io/dns/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"dns_lookup","arguments":{"domain":"gmail.com","type":"MX"}}}'

The setup configuration also registers that gateway:

json
{
  "mcpServers": {
    "pipeworx-dns": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/dns/mcp"]
    }
  }
}

Technical Analysis

DNS lookup targets are transmitted to gateway.pipeworx.io, not directly to a Google DNS-over-HTTPS endpoint. HTTPS protects the request while it is in transit, but the Pipeworx endpoint necessarily receives the submitted domain or reverse-lookup IP address.

The Skill does not clearly explain that Pipeworx acts as an intermediary, nor does it document the intermediary's logging, retention, secondary-use, or deletion practices. Domain names and IP addresses can be sensitive when they identify internal infrastructure, incident-response targets, prospective acquisitions, customers, or other investigative activity.

The reviewed file does not establish that Pipeworx misuses this information. The issue is the undisclosed or insufficiently documented transfer and trust boundary.

Attack Path

  1. A user asks the Agent to resolve a domain name or perform a reverse lookup.
  2. The Agent submits the loo ...[truncated 749 chars]
Remediation
View remediation

Remediation Suggestions

  • Clearly state that lookup targets are sent to and processed by Pipeworx before any downstream DNS resolution.
  • Document the gateway's privacy policy, logging behavior, data-retention period, deletion process, hosting jurisdiction, and subprocessors.
  • Obtain explicit user approval before transmitting potentially sensitive domains or IP addresses.
  • Where possible, query an explicitly selected DNS-over-HTTPS endpoint directly rather than routing requests through an additional intermediary.
  • Minimize transmitted metadata and avoid submitting private hostnames or sensitive investigation targets to an external service.
  • For sensitive environments, support a user-controlled resolver or a locally hosted MCP implementation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "🔍"
    homepage: https://pipeworx.io/packs/dns
---

Static analysis

No suspicious patterns detected.