Back to skill

Security audit

Pipeworx newton

Security checks for vulnerabilities and agentic risk

Overview

This math skill is clear about using an external API, but its setup runs an automatically updated npm package, so it should be reviewed before installation.

Before installing, be comfortable sending entered math expressions to PipeWorx's gateway and running a local npm-based MCP adapter. Prefer pinning mcp-remote to an exact reviewed version and running the MCP process with limited local permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:54
Finding

Unpinned npm Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54-60
Vulnerability Type: Unsafe execution of a mutable third-party dependency
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-newton": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/newton/mcp"]
    }
  }
}

Technical Analysis

The setup configuration invokes npx with mcp-remote@latest. The latest npm tag is mutable, so the package code executed by future installations is not fixed to the version that was available when the skill was audited. The -y option suppresses the normal installation confirmation.

As a result, following the documented setup can download and execute third-party package code that was not included in this project and whose effective implementation can change after review. npm package installation and startup behavior may execute lifecycle scripts or runtime code with the privileges of the user launching the MCP server.

This finding concerns the package execution mechanism. The reviewed file provides no evidence that the current mcp-remote package is malicious.

Attack Path

  1. An attacker compromises the upstream npm package, a maintainer account, or the package publication process.
  2. The attacker publishes a malicious release and assigns it to the mutable latest tag.
  3. A user applies the documented configuration and starts the MCP server.
  4. npx -y mcp-remote@latest retrieves the attacker-controlled release without requesting interactive confirmation.
  5. Malicious lifecycle or runtime code executes in the local context of the user who launched the process.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the Agent or user running npx. Depending on that account's permissions and environment, the malicious package could read or modify accessible f ...[truncated 292 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an audited, exact package version, such as mcp-remote@x.y.z.
  • Use a lockfile and integrity verification where the deployment mechanism supports them.
  • Remove -y when practical so unexpected package installation requires explicit confirmation.
  • Retrieve packages only from an approved registry and apply registry access controls.
  • Review the pinned package, including its dependency tree and npm lifecycle scripts, before deployment.
  • Run the MCP process in a sandbox or dedicated least-privilege account with narrowly scoped filesystem, credential, and network access.
  • Establish a controlled update process that reviews and tests each new version before changing the pin.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

Example: derivative of sin(x)*x^2

bash
curl -s -X POST https://gateway.pipeworx.io/newton/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"derive","arguments":{"expression":"x^3+2x^2+x"}}}'

Static analysis

No suspicious patterns detected.