Back to skill

Security audit

Pipeworx hackernews

Security checks for vulnerabilities and agentic risk

Overview

This Hacker News skill is purpose-aligned, but its connection instructions run an unpinned third-party package that can change after review.

Install only if you are comfortable sending Hacker News queries through Pipeworx and running an MCP bridge from npm. Prefer pinning mcp-remote to a reviewed exact version and running it in a restricted environment, especially if queries may include confidential company, incident, or research terms.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:44
Finding

Unpinned Third-Party Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 44-47
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: Medium

json
"pipeworx-hackernews": {
  "command": "npx",
  "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/hackernews/mcp"]
}

Technical Analysis

The documented configuration invokes npx with the -y option and the mutable package specifier mcp-remote@latest. This causes npm to download and execute whichever package version is tagged as latest at invocation time, without interactive confirmation.

The effective executable is neither included in this project nor pinned to an audited version or integrity digest. Consequently, its behavior can change after this Skill has been reviewed. Compromise of the package publisher, npm account, package distribution channel, or a future malicious release could introduce arbitrary local code execution.

Attack Path

  1. An attacker compromises the mcp-remote package, its publisher account, or its release process, or publishes a malicious future release through an otherwise authorized account.
  2. The malicious release is assigned the npm latest tag.
  3. A user follows the connection instructions in SKILL.md.
  4. npx -y retrieves the attacker-controlled release without requesting confirmation.
  5. The package executes locally with the permissions of the user or agent process that launched it.
  6. The malicious package can access resources available to that process, subject to operating-system controls and sandboxing.

Impact Assessment

Successful exploitation could result in arbitrary code execution with the invoking user's privileges. Depending on the execution environment, this may permit access to readable files, environment variables, agent configuration, network resources, and credentials available to the process. It could also allow modification of user-owned data or ex ...[truncated 172 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with a specifically reviewed, exact package version.
  • Verify the package against a trusted integrity digest and use a lockfile where the deployment mechanism supports one.
  • Avoid npx -y for security-sensitive installation or execution flows; require explicit user confirmation before downloading executable dependencies.
  • Prefer a vendored or locally installed, reviewed client whose source and dependency tree are included in the audit scope.
  • Run the MCP client with least privilege in a restricted environment that limits filesystem access, environment variables, credentials, and outbound network destinations.
  • Establish a controlled dependency-update process in which new versions are reviewed and tested before deployment.

other

Note
Location
SKILL.md:31
Finding

Hacker News Queries Are Disclosed to a Third-Party Gateway

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31-33 and line 47
Vulnerability Type: Third-party data exposure
Risk Level: Low

bash
curl -s -X POST https://gateway.pipeworx.io/hackernews/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_hn","arguments":{"query":"Rust programming language","sort":"points","limit":5}}}'

The same external service is also configured as the MCP endpoint:

json
"args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/hackernews/mcp"]

Technical Analysis

Search terms and MCP request metadata are sent to gateway.pipeworx.io, an intermediary operated separately from the named Hacker News Algolia and Firebase APIs. The destination is visible in the documentation, so the transmission is not covert. However, the Skill does not explain the gateway's data handling, retention, logging, or onward-sharing practices.

Although the example query is harmless, users may submit company names, unreleased project details, incident information, security research topics, or other sensitive contextual data. These values would become available to the gateway operator and any infrastructure involved in processing or logging the requests.

Attack Path

  1. A user submits a Hacker News search or item request through the Skill.
  2. The MCP client forwards the request to https://gateway.pipeworx.io/hackernews/mcp.
  3. The third-party gateway receives the query and associated request metadata.
  4. The data may be processed or retained according to policies not documented in this project.
  5. If the gateway, its logs, or its infrastructure are misused or compromised, the submitted information may be disclosed to unauthorized parties.

Impact Assessment

The principal impact is loss of confidentiality for search terms, item requests, and related metadata. This issue does not, by itself, gr ...[truncated 198 chars]

Remediation
View remediation

Remediation Suggestions

  • Clearly disclose that requests are transmitted to Pipeworx rather than directly to the official Hacker News APIs.
  • Document the gateway's privacy policy, logging behavior, retention period, subprocessors, and deletion procedures.
  • Warn users not to include credentials, personal data, confidential project names, incident details, or other sensitive information in queries.
  • Obtain explicit user approval before transmitting potentially sensitive request content to the third party.
  • Minimize request metadata and disable unnecessary server-side logging.
  • Where feasible, provide a mode that accesses the official Hacker News Algolia and Firebase APIs directly.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "📰"
    homepage: https://pipeworx.io/packs/hackernews
---

Static analysis

No suspicious patterns detected.