Back to skill

Security audit

Pipeworx nominatim

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide the advertised geocoding function, but its setup runs an unpinned npm package automatically, which makes the installed code broader than the reviewed artifact.

Before installing, pin `mcp-remote` to a reviewed version if possible, run it with least privilege, and assume address or coordinate queries submitted through the skill are sent to the Pipeworx gateway for processing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Unpinned npm Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–50
Vulnerability Type: Supply-chain risk caused by automatic execution of a mutable dependency
Risk Level: Medium

Complete Code Snippet:

markdown
## Setup

```json
{
  "mcpServers": {
    "pipeworx-nominatim": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/nominatim/mcp"]
    }
  }
}
text

### Technical Analysis

The setup directs `npx` to resolve, download, and execute `mcp-remote@latest`. The `-y` option suppresses the interactive confirmation that would otherwise alert the user before package installation. The mutable `@latest` tag does not identify the package version that was reviewed and can resolve to different code during future installations.

Consequently, the effective locally executed code is controlled by the package version available from the npm registry at setup time. If the package publisher account, release pipeline, registry path, or a future release is compromised, arbitrary package code could execute without any modification to this repository. This is an insecure dependency configuration rather than evidence that the currently published package is malicious.

### Attack Path

1. An attacker compromises the npm publisher account or release pipeline for `mcp-remote`, or otherwise causes a malicious release to become the version referenced by `latest`.
2. A user applies the documented MCP setup.
3. The MCP host invokes `npx` with `-y`.
4. `npx` resolves `mcp-remote@latest` to the attacker-controlled release and downloads it without confirmation.
5. Package installation hooks or runtime entry-point code executes locally under the account running the MCP host.
6. The malicious code can perform actions available to that account.

### Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running `np
...[truncated 396 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed version such as mcp-remote@x.y.z.
  • Maintain a lockfile and verify package integrity through a trusted checksum or registry integrity metadata.
  • Review the pinned package, including installation scripts and transitive dependencies, before deployment.
  • Use a controlled dependency mirror or allowlist where practical.
  • Remove -y when interactive approval is appropriate so unexpected package installation is not silently accepted.
  • Run the MCP process as a dedicated, least-privileged account or inside a restricted container with only necessary filesystem and network access.
  • Establish a deliberate update process that reviews and tests each dependency version before changing the pin.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Example: where is the Sydney Opera House?

bash
curl -s -X POST https://gateway.pipeworx.io/nominatim/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_address","arguments":{"query":"Sydney Opera House, Australia","limit":1}}}'

Static analysis

No suspicious patterns detected.