T08 · Insecure Dependencies
- Location
SKILL.md:45- Finding
Automatic Execution of an Unpinned Third-Party npm Package
- Content
View full analysis
- Remediation
View remediation
", "https://gateway.pipeworx.io/iconify/mcp"] ``` 2. Remove `-y` so that unexpected package installation does not proceed automatically. 3. Install the dependency through a committed lockfile and use a reproducible installation method such as `npm ci`. 4. Verify the package using registry integrity metadata, cryptographic provenance, and publisher/repository ownership before deployment. 5. Prefer a locally installed, audited launcher rather than downloading executable code at MCP startup. 6. Use dependency monitoring and require explicit review before updating the pinned version. 7. Run the MCP launcher in a restricted environment with minimal filesystem access, limited credentials, constrained network access, and no administrative privileges. ]]>
