T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 54-60
Vulnerability Type: Unsafe execution of a mutable third-party dependency
Risk Level: MediumVulnerable Code
json { "mcpServers": { "pipeworx-newton": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/newton/mcp"] } } }Technical Analysis
The setup configuration invokes
npxwithmcp-remote@latest. Thelatestnpm tag is mutable, so the package code executed by future installations is not fixed to the version that was available when the skill was audited. The-yoption suppresses the normal installation confirmation.As a result, following the documented setup can download and execute third-party package code that was not included in this project and whose effective implementation can change after review. npm package installation and startup behavior may execute lifecycle scripts or runtime code with the privileges of the user launching the MCP server.
This finding concerns the package execution mechanism. The reviewed file provides no evidence that the current
mcp-remotepackage is malicious.Attack Path
- An attacker compromises the upstream npm package, a maintainer account, or the package publication process.
- The attacker publishes a malicious release and assigns it to the mutable
latesttag. - A user applies the documented configuration and starts the MCP server.
npx -y mcp-remote@latestretrieves the attacker-controlled release without requesting interactive confirmation.- Malicious lifecycle or runtime code executes in the local context of the user who launched the process.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the Agent or user running
npx. Depending on that account's permissions and environment, the malicious package could read or modify accessible f ...[truncated 292 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an audited, exact package version, such asmcp-remote@x.y.z. - Use a lockfile and integrity verification where the deployment mechanism supports them.
- Remove
-ywhen practical so unexpected package installation requires explicit confirmation. - Retrieve packages only from an approved registry and apply registry access controls.
- Review the pinned package, including its dependency tree and npm lifecycle scripts, before deployment.
- Run the MCP process in a sandbox or dedicated least-privilege account with narrowly scoped filesystem, credential, and network access.
- Establish a controlled update process that reviews and tests each new version before changing the pin.
- Replace
