T08 · Insecure Dependencies
- Location
SKILL.md:43- Finding
Automatic Execution of an Unpinned Remote Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–48
Vulnerability Type: Supply-chain risk from mutable dependency execution
Risk Level: Mediumjson { "mcpServers": { "pipeworx-treasury": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/treasury/mcp"] } } }Technical Analysis
The documented setup invokes
npxwith the-yoption and the mutable package specifiermcp-remote@latest. When the MCP server starts,npxmay download and execute whichever package release the registry resolves aslatestat that time. The command does not pin an audited version or provide an integrity constraint.Consequently, the code executed by users can differ from the code that existed when this Skill was reviewed. The issue becomes exploitable if the package, its publishing account, the package registry, or an upstream dependency is compromised. The available project content does not establish that the current package is malicious; the vulnerability is the unsafe trust and execution model.
Attack Path
- An attacker compromises the
mcp-remotepackage, its publisher account, its dependency chain, or the relevant package-distribution infrastructure. - The attacker publishes a malicious release and causes the
latesttag to resolve to it. - A user configures or launches the Skill using the documented MCP setup.
npx -yretrieves the attacker-controlled release without requiring interactive approval.- The package executes locally with the permissions and environment available to the Agent process.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the account that launches the MCP server. Depending on that account's privileges and environment, the malicious package could read accessible files and environment variables, access credentials available to the process, modify user-owned data, make network requests, or interfere w ...[truncated 137 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version such asmcp-remote@x.y.z. - Install the dependency through a lockfile-controlled workflow and verify registry integrity metadata.
- Avoid automatic package acquisition and execution during routine Skill startup.
- Review the pinned package and its transitive dependencies before deployment.
- Use a trusted internal registry or approved package mirror where appropriate.
- Run the MCP process in a sandbox with minimal filesystem, environment-variable, credential, and network access.
- Establish an explicit dependency-update process that includes security review and testing before changing the pinned version.
- Replace
