T08 · Insecure Dependencies
- Location
SKILL.md:41- Finding
Unpinned Third-Party Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 41-50
Vulnerability Type: Unpinned remote dependency execution
Risk Level: HighVulnerable Code
json { "mcpServers": { "pipeworx-imgflip": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/imgflip/mcp"] } } }Technical Analysis
The MCP configuration invokes
npxwith the-yoption and the mutable dependency specifiermcp-remote@latest. When this configuration is used,npxmay automatically download and execute the version currently associated with the package'slatestdistribution tag without user confirmation.Because the package version and integrity digest are not pinned, the locally executed code can change after the Skill has been reviewed. A compromised package maintainer account, package registry, release process, or future malicious release could therefore turn this configuration into a supply-chain code-execution channel.
The fixed HTTPS MCP endpoint does not mitigate the risk arising from the locally executed npm package. No evidence establishes that the current package version is malicious; the vulnerability is the unsafe, mutable dependency-resolution and execution mechanism.
Attack Path
- An attacker compromises the
mcp-remotepackage, its maintainer credentials, or its release pipeline, or otherwise causes a malicious release to receive thelatesttag. - A user installs or launches the documented MCP configuration.
npx -yresolves and downloads the attacker-controlled latest package version without an interactive confirmation prompt.- The downloaded package executes locally under the privileges of the user or agent process.
- The malicious package can access resources available to that process and may manipulate MCP communications or perform additional actions permitted by the host environment.
Impact Assessment
Suc ...[truncated 587 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version such asmcp-remote@X.Y.Z; do not use a mutable tag or version range. - Record and verify the package integrity hash through a lockfile or equivalent package-verification mechanism.
- Install dependencies during a controlled deployment step rather than downloading executable code automatically whenever the MCP server starts.
- Disable automatic confirmation where practical and require explicit review before dependency installation or upgrades.
- Restrict package installation to a trusted registry and protect configuration against registry substitution or dependency-confusion attacks.
- Review new package versions before upgrading, including package lifecycle scripts, transitive dependencies, provenance, and published artifacts.
- Run the MCP process in a least-privilege sandbox with narrowly scoped filesystem, environment-variable, credential, and network access.
- Consider vendoring or internally mirroring the audited package artifact so the executed dependency remains reproducible and available for independent verification.
- Replace
