T08 · Insecure Dependencies
- Location
SKILL.md:43- Finding
Automatic Execution of an Unpinned npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43-49
Vulnerability Type: Supply-chain risk caused by a mutable dependency version
Risk Level: HighVulnerable Code
json { "mcpServers": { "pipeworx-dns": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/dns/mcp"] } } }Technical Analysis
The setup configuration invokes
npxwith both the automatic-confirmation option (-y) and the mutable version selectormcp-remote@latest. Consequently, setup can download and execute a dependency release that did not exist when the Skill was audited.The package is not pinned to an exact audited version, and the configuration provides no lockfile or integrity hash with which to verify the downloaded artifact. If the npm package, maintainer account, publishing pipeline, or dependency chain is compromised, a malicious release selected by
latestcan execute locally without an additional confirmation prompt.This is a supply-chain weakness rather than evidence that the currently published package is malicious.
Attack Path
- An attacker compromises the
mcp-remotepackage, its maintainer account, its publishing infrastructure, or a transitive dependency. - The attacker publishes a malicious version that becomes the package's
latestrelease. - A user applies the documented MCP configuration.
npx -yresolves and downloads the attacker-controlled release without interactive confirmation.- The downloaded package executes under the identity and environment of the user running the Agent.
- Malicious package code can access resources available to that user and initiate additional network or process activity.
Impact Assessment
Successful exploitation would provide code execution with the privileges of the Agent user. The potential scope includes readable or writable files belonging to that account, environm ...[truncated 275 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version, such asmcp-remote@<audited-version>. - Use a lockfile and package-manager integrity metadata to make dependency resolution reproducible.
- Avoid automatic execution of newly downloaded packages during setup. Install and review the dependency separately before invocation.
- Monitor the pinned package and its transitive dependencies for security advisories.
- Run the MCP client with least privilege in a sandbox or container, with restricted filesystem, credential, process, and network access.
- Require explicit review and testing before updating the pinned version.
- Replace
