Back to skill

Security audit

Pipeworx nhtsa

Security checks for vulnerabilities and agentic risk

Overview

This vehicle lookup skill does what it claims, but its setup runs a mutable npm package with local user permissions, which users should review before installing.

Install only if you are comfortable sending VIN or vehicle lookup inputs to Pipeworx and running the documented MCP bridge locally. Prefer changing the config to a pinned mcp-remote version, run it in a restricted environment, and avoid exposing unrelated project files, credentials, or environment variables to the process.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Third-Party Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–50
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

json
{
  "mcpServers": {
    "pipeworx-nhtsa": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/nhtsa/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration invokes npx with -y to download and execute mcp-remote@latest. The latest tag is mutable, so the package code executed in the future may differ from the version available when the skill was reviewed. The -y option suppresses the installation confirmation, while the configuration provides no exact version pin, lockfile, or integrity hash.

Consequently, compromise of the package, its maintainer account, or the npm publication pipeline could turn normal skill setup into arbitrary local code execution. This is a supply-chain weakness rather than evidence that the package is currently malicious.

Attack Path

  1. An attacker compromises the mcp-remote package, a maintainer account, or its release process.
  2. The attacker publishes a malicious release and assigns it to the npm latest tag.
  3. A user or agent starts the documented MCP server configuration.
  4. npx -y mcp-remote@latest downloads the attacker-controlled release without an interactive confirmation.
  5. Package installation hooks or runtime code execute with the permissions of the user running the agent.
  6. The malicious code can access resources available to that account and perform actions within those permission boundaries.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the operating-system account that launches the MCP configuration. Depending on that account's permissions and environment, an attacker could read or alter accessible project files, inspect environment variables and locally available cred ...[truncated 370 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed version, such as mcp-remote@x.y.z.
  • Install dependencies from a committed lockfile that records package integrity hashes.
  • Prefer a controlled installation phase over downloading and executing a package dynamically whenever the MCP server starts.
  • Remove -y where practical so unexpected installation activity requires explicit approval.
  • Verify package provenance and signatures when supported, and review release ownership and package lifecycle scripts.
  • Run the MCP process in a sandbox or restricted account with minimal filesystem, credential, and network access.
  • Establish an update process in which new versions are reviewed and tested before the pinned version is changed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "🚗"
    homepage: https://pipeworx.io/packs/nhtsa
---

Static analysis

No suspicious patterns detected.