T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Third-Party Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This trivia skill is coherent, but its MCP setup runs an unpinned npm package automatically, which deserves review before installation.
Install only if you are comfortable running a remote MCP bridge via npm. Prefer pinning `mcp-remote` to a reviewed exact version, running it in a restricted environment, and keeping credentials or sensitive environment variables out of that process.
SKILL.md:54Unpinned Third-Party Package Is Automatically Downloaded and Executed
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
openclaw:
requires:
bins:
- curl
emoji: "🧠"
homepage: https://pipeworx.io/packs/trivia
---
No suspicious patterns detected.