T08 · Insecure Dependencies
- Location
SKILL.md:43- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–50
Vulnerability Type: Supply-chain risk caused by automatic execution of a mutable dependency
Risk Level: MediumComplete Code Snippet:
markdown ## Setup ```json { "mcpServers": { "pipeworx-nominatim": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/nominatim/mcp"] } } }text ### Technical Analysis The setup directs `npx` to resolve, download, and execute `mcp-remote@latest`. The `-y` option suppresses the interactive confirmation that would otherwise alert the user before package installation. The mutable `@latest` tag does not identify the package version that was reviewed and can resolve to different code during future installations. Consequently, the effective locally executed code is controlled by the package version available from the npm registry at setup time. If the package publisher account, release pipeline, registry path, or a future release is compromised, arbitrary package code could execute without any modification to this repository. This is an insecure dependency configuration rather than evidence that the currently published package is malicious. ### Attack Path 1. An attacker compromises the npm publisher account or release pipeline for `mcp-remote`, or otherwise causes a malicious release to become the version referenced by `latest`. 2. A user applies the documented MCP setup. 3. The MCP host invokes `npx` with `-y`. 4. `npx` resolves `mcp-remote@latest` to the attacker-controlled release and downloads it without confirmation. 5. Package installation hooks or runtime entry-point code executes locally under the account running the MCP host. 6. The malicious code can perform actions available to that account. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the privileges of the user running `np ...[truncated 396 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version such asmcp-remote@x.y.z. - Maintain a lockfile and verify package integrity through a trusted checksum or registry integrity metadata.
- Review the pinned package, including installation scripts and transitive dependencies, before deployment.
- Use a controlled dependency mirror or allowlist where practical.
- Remove
-ywhen interactive approval is appropriate so unexpected package installation is not silently accepted. - Run the MCP process as a dedicated, least-privileged account or inside a restricted container with only necessary filesystem and network access.
- Establish a deliberate update process that reviews and tests each dependency version before changing the pin.
- Replace
