T08 · Insecure Dependencies
- Location
SKILL.md:41- Finding
Unpinned Third-Party MCP Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 41–45
Vulnerability Type: Insecure third-party dependency execution
Risk Level: MediumVulnerable Code
json { "mcpServers": { "pipeworx-domains": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/domains/mcp"] } } }Technical Analysis
The MCP configuration invokes
npxwith the-yoption to download and executemcp-remote@latestwithout interactive confirmation. The mutablelatesttag does not identify a fixed, audited package version and provides no integrity guarantee. Consequently, the code executed during Skill setup may differ from the version that existed when the Skill was reviewed.This creates a supply-chain execution path in which compromise of the npm package, its maintainer account, publishing process, or transitive dependencies could introduce malicious code. Because
npxexecutes the downloaded package locally, such code would run with the privileges of the user or agent process launching the MCP server.Attack Path
- An attacker compromises the
mcp-remotenpm package, a maintainer account, its release pipeline, or a dependency included in a new release. - The attacker publishes a malicious version and assigns or causes it to receive the
latestdistribution tag. - A user or agent applies the documented MCP configuration.
npx -y mcp-remote@latestretrieves the attacker-controlled package without asking for confirmation.- Package initialization or runtime code executes on the local system with the invoking process's permissions.
- The malicious code can access resources available to that process and perform actions within those permission boundaries.
Impact Assessment
Successful exploitation could permit arbitrary local code execution with the privileges of the user or agent that launches the MCP server. Depending on those privileges and the surrounding environment, th ...[truncated 447 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version such asmcp-remote@x.y.z; do not use mutable tags or version ranges. - Install dependencies through a committed lockfile that records exact transitive versions and integrity hashes.
- Verify package provenance, signatures, and registry integrity metadata before installation where supported.
- Remove unattended installation via
npx -ywhere practical, or require administrators to review and install the dependency separately. - Prefer a bundled and audited client or a locally installed MCP implementation from a controlled artifact repository.
- Run the MCP process with least privilege in a sandbox or container, restricting filesystem access, environment variables, credentials, process execution, and outbound network destinations.
- Establish dependency monitoring and a controlled update process so new versions are reviewed and tested before deployment.
- Replace
