T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Third-Party Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–50
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
json { "mcpServers": { "pipeworx-nhtsa": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/nhtsa/mcp"] } } }Technical Analysis
The MCP configuration invokes
npxwith-yto download and executemcp-remote@latest. Thelatesttag is mutable, so the package code executed in the future may differ from the version available when the skill was reviewed. The-yoption suppresses the installation confirmation, while the configuration provides no exact version pin, lockfile, or integrity hash.Consequently, compromise of the package, its maintainer account, or the npm publication pipeline could turn normal skill setup into arbitrary local code execution. This is a supply-chain weakness rather than evidence that the package is currently malicious.
Attack Path
- An attacker compromises the
mcp-remotepackage, a maintainer account, or its release process. - The attacker publishes a malicious release and assigns it to the npm
latesttag. - A user or agent starts the documented MCP server configuration.
npx -y mcp-remote@latestdownloads the attacker-controlled release without an interactive confirmation.- Package installation hooks or runtime code execute with the permissions of the user running the agent.
- The malicious code can access resources available to that account and perform actions within those permission boundaries.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the operating-system account that launches the MCP configuration. Depending on that account's permissions and environment, an attacker could read or alter accessible project files, inspect environment variables and locally available cred ...[truncated 370 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version, such asmcp-remote@x.y.z. - Install dependencies from a committed lockfile that records package integrity hashes.
- Prefer a controlled installation phase over downloading and executing a package dynamically whenever the MCP server starts.
- Remove
-ywhere practical so unexpected installation activity requires explicit approval. - Verify package provenance and signatures when supported, and review release ownership and package lifecycle scripts.
- Run the MCP process in a sandbox or restricted account with minimal filesystem, credential, and network access.
- Establish an update process in which new versions are reviewed and tested before the pinned version is changed.
- Replace
