Back to skill

Security audit

Pipeworx domains

Security checks for vulnerabilities and agentic risk

Overview

The skill's domain-search behavior is clear, but its MCP setup runs an unpinned third-party npm package locally.

Review the MCP setup before installing. The domain search itself is purpose-aligned, but use a pinned and trusted mcp-remote version or a controlled installation path if possible, and run it with only the filesystem, environment variables, and network access it needs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:41
Finding

Unpinned Third-Party MCP Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 41–45
Vulnerability Type: Insecure third-party dependency execution
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-domains": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/domains/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration invokes npx with the -y option to download and execute mcp-remote@latest without interactive confirmation. The mutable latest tag does not identify a fixed, audited package version and provides no integrity guarantee. Consequently, the code executed during Skill setup may differ from the version that existed when the Skill was reviewed.

This creates a supply-chain execution path in which compromise of the npm package, its maintainer account, publishing process, or transitive dependencies could introduce malicious code. Because npx executes the downloaded package locally, such code would run with the privileges of the user or agent process launching the MCP server.

Attack Path

  1. An attacker compromises the mcp-remote npm package, a maintainer account, its release pipeline, or a dependency included in a new release.
  2. The attacker publishes a malicious version and assigns or causes it to receive the latest distribution tag.
  3. A user or agent applies the documented MCP configuration.
  4. npx -y mcp-remote@latest retrieves the attacker-controlled package without asking for confirmation.
  5. Package initialization or runtime code executes on the local system with the invoking process's permissions.
  6. The malicious code can access resources available to that process and perform actions within those permission boundaries.

Impact Assessment

Successful exploitation could permit arbitrary local code execution with the privileges of the user or agent that launches the MCP server. Depending on those privileges and the surrounding environment, th ...[truncated 447 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace mcp-remote@latest with an exact, reviewed version such as mcp-remote@x.y.z; do not use mutable tags or version ranges.
  2. Install dependencies through a committed lockfile that records exact transitive versions and integrity hashes.
  3. Verify package provenance, signatures, and registry integrity metadata before installation where supported.
  4. Remove unattended installation via npx -y where practical, or require administrators to review and install the dependency separately.
  5. Prefer a bundled and audited client or a locally installed MCP implementation from a controlled artifact repository.
  6. Run the MCP process with least privilege in a sandbox or container, restricting filesystem access, environment variables, credentials, process execution, and outbound network destinations.
  7. Establish dependency monitoring and a controlled update process so new versions are reviewed and tested before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "🌐"
    homepage: https://pipeworx.io/packs/domains
---

Static analysis

No suspicious patterns detected.