T08 · Insecure Dependencies
- Location
SKILL.md:56- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56–62
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: Mediumjson { "mcpServers": { "pipeworx-zippopotam": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/zippopotam/mcp"] } } }Technical Analysis
The MCP configuration invokes
npxwithmcp-remote@latestand the automatic-confirmation option-y. When the package is not already available locally,npxcan retrieve it from the configured npm registry and execute its entry point. Thelatesttag is mutable and therefore does not identify the exact package version that was audited.Consequently, the code executed by this configuration may change without any corresponding change to the Skill. If the package, its maintainer account, its release process, or a transitive dependency is compromised, a malicious release assigned to
latestcould execute arbitrary code under the invoking user's account. The reviewed material does not establish that the current package is malicious; this finding concerns the unsafe dependency-execution mechanism.Attack Path
- An attacker compromises the
mcp-remotepublishing account, package release process, or relevant dependency chain. - The attacker publishes a malicious package version and causes the npm
latesttag to resolve to it. - A user loads the supplied MCP configuration.
npx -y mcp-remote@latestretrieves the attacker-controlled release without interactive confirmation.- The package entry point executes locally with the permissions and environment available to the MCP host process.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user running the Agent or MCP host. Depending on that user's permissions and environment, the malicious package could read or alt ...[truncated 373 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version such asmcp-remote@X.Y.Z; do not use mutable distribution tags or version ranges. - Install dependencies through a committed lockfile and use a reproducible installation mode such as
npm ci. - Verify package provenance, publisher identity, release signatures where available, and registry integrity metadata before deployment.
- Review the pinned package and its transitive dependency tree, and repeat that review before upgrading.
- Avoid
npx -yfor first-time or untrusted package execution. Require an explicit installation and approval step instead. - Run the MCP process in a restricted environment with minimal filesystem access, a sanitized environment, no unnecessary credentials, and constrained outbound network access.
- Establish an upgrade process that tests and approves each exact dependency version before changing the pin.
- Replace
