Back to skill

Security audit

Pipeworx imgflip

Security checks for vulnerabilities and agentic risk

Overview

The skill’s meme-template lookup purpose is coherent, but its documented MCP setup runs an unpinned npm package with automatic confirmation, which should be reviewed before installation.

Review this skill before installing. The data lookup itself is simple and appears limited to public meme-template metadata, but the MCP setup should ideally pin mcp-remote to a reviewed version and run in a least-privilege environment. Be cautious about installing it where the agent process has access to sensitive files, environment variables, or credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:41
Finding

Unpinned Third-Party Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 41-50
Vulnerability Type: Unpinned remote dependency execution
Risk Level: High

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-imgflip": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/imgflip/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration invokes npx with the -y option and the mutable dependency specifier mcp-remote@latest. When this configuration is used, npx may automatically download and execute the version currently associated with the package's latest distribution tag without user confirmation.

Because the package version and integrity digest are not pinned, the locally executed code can change after the Skill has been reviewed. A compromised package maintainer account, package registry, release process, or future malicious release could therefore turn this configuration into a supply-chain code-execution channel.

The fixed HTTPS MCP endpoint does not mitigate the risk arising from the locally executed npm package. No evidence establishes that the current package version is malicious; the vulnerability is the unsafe, mutable dependency-resolution and execution mechanism.

Attack Path

  1. An attacker compromises the mcp-remote package, its maintainer credentials, or its release pipeline, or otherwise causes a malicious release to receive the latest tag.
  2. A user installs or launches the documented MCP configuration.
  3. npx -y resolves and downloads the attacker-controlled latest package version without an interactive confirmation prompt.
  4. The downloaded package executes locally under the privileges of the user or agent process.
  5. The malicious package can access resources available to that process and may manipulate MCP communications or perform additional actions permitted by the host environment.

Impact Assessment

Suc ...[truncated 587 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed version such as mcp-remote@X.Y.Z; do not use a mutable tag or version range.
  • Record and verify the package integrity hash through a lockfile or equivalent package-verification mechanism.
  • Install dependencies during a controlled deployment step rather than downloading executable code automatically whenever the MCP server starts.
  • Disable automatic confirmation where practical and require explicit review before dependency installation or upgrades.
  • Restrict package installation to a trusted registry and protect configuration against registry substitution or dependency-confusion attacks.
  • Review new package versions before upgrading, including package lifecycle scripts, transitive dependencies, provenance, and published artifacts.
  • Run the MCP process in a least-privilege sandbox with narrowly scoped filesystem, environment-variable, credential, and network access.
  • Consider vendoring or internally mirroring the audited package artifact so the executed dependency remains reproducible and available for independent verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "😂"
    homepage: https://pipeworx.io/packs/imgflip
---

Static analysis

No suspicious patterns detected.