Back to skill

Security audit

Pipeworx treasury

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for querying US Treasury data, but its setup runs a mutable remote npm package with local execution authority.

Review this before installing because startup may execute a changing npm package on your machine. Prefer pinning `mcp-remote` to a reviewed version and running it with minimal filesystem, environment-variable, and credential access. The remote Treasury data calls themselves are disclosed and purpose-aligned.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Automatic Execution of an Unpinned Remote Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–48
Vulnerability Type: Supply-chain risk from mutable dependency execution
Risk Level: Medium

json
{
  "mcpServers": {
    "pipeworx-treasury": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/treasury/mcp"]
    }
  }
}

Technical Analysis

The documented setup invokes npx with the -y option and the mutable package specifier mcp-remote@latest. When the MCP server starts, npx may download and execute whichever package release the registry resolves as latest at that time. The command does not pin an audited version or provide an integrity constraint.

Consequently, the code executed by users can differ from the code that existed when this Skill was reviewed. The issue becomes exploitable if the package, its publishing account, the package registry, or an upstream dependency is compromised. The available project content does not establish that the current package is malicious; the vulnerability is the unsafe trust and execution model.

Attack Path

  1. An attacker compromises the mcp-remote package, its publisher account, its dependency chain, or the relevant package-distribution infrastructure.
  2. The attacker publishes a malicious release and causes the latest tag to resolve to it.
  3. A user configures or launches the Skill using the documented MCP setup.
  4. npx -y retrieves the attacker-controlled release without requiring interactive approval.
  5. The package executes locally with the permissions and environment available to the Agent process.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the account that launches the MCP server. Depending on that account's privileges and environment, the malicious package could read accessible files and environment variables, access credentials available to the process, modify user-owned data, make network requests, or interfere w ...[truncated 137 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed version such as mcp-remote@x.y.z.
  • Install the dependency through a lockfile-controlled workflow and verify registry integrity metadata.
  • Avoid automatic package acquisition and execution during routine Skill startup.
  • Review the pinned package and its transitive dependencies before deployment.
  • Use a trusted internal registry or approved package mirror where appropriate.
  • Run the MCP process in a sandbox with minimal filesystem, environment-variable, credential, and network access.
  • Establish an explicit dependency-update process that includes security review and testing before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Example: current national debt

bash
curl -s -X POST https://gateway.pipeworx.io/treasury/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"get_national_debt","arguments":{}}}'

Static analysis

No suspicious patterns detected.