Back to skill

Security audit

Pipeworx zippopotam

Security checks for vulnerabilities and agentic risk

Overview

This postal-code lookup skill is purpose-aligned, but its MCP setup runs a mutable npm package locally, which users should review before installing.

Install only if you are comfortable with lookup queries being sent to Pipeworx and with the MCP host running `mcp-remote` from npm. Prefer pinning `mcp-remote` to a reviewed version or installing it through a controlled dependency process before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:56
Finding

Unpinned npm Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56–62
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: Medium

json
{
  "mcpServers": {
    "pipeworx-zippopotam": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/zippopotam/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration invokes npx with mcp-remote@latest and the automatic-confirmation option -y. When the package is not already available locally, npx can retrieve it from the configured npm registry and execute its entry point. The latest tag is mutable and therefore does not identify the exact package version that was audited.

Consequently, the code executed by this configuration may change without any corresponding change to the Skill. If the package, its maintainer account, its release process, or a transitive dependency is compromised, a malicious release assigned to latest could execute arbitrary code under the invoking user's account. The reviewed material does not establish that the current package is malicious; this finding concerns the unsafe dependency-execution mechanism.

Attack Path

  1. An attacker compromises the mcp-remote publishing account, package release process, or relevant dependency chain.
  2. The attacker publishes a malicious package version and causes the npm latest tag to resolve to it.
  3. A user loads the supplied MCP configuration.
  4. npx -y mcp-remote@latest retrieves the attacker-controlled release without interactive confirmation.
  5. The package entry point executes locally with the permissions and environment available to the MCP host process.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running the Agent or MCP host. Depending on that user's permissions and environment, the malicious package could read or alt ...[truncated 373 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mcp-remote@latest with an exact, reviewed version such as mcp-remote@X.Y.Z; do not use mutable distribution tags or version ranges.
  • Install dependencies through a committed lockfile and use a reproducible installation mode such as npm ci.
  • Verify package provenance, publisher identity, release signatures where available, and registry integrity metadata before deployment.
  • Review the pinned package and its transitive dependency tree, and repeat that review before upgrading.
  • Avoid npx -y for first-time or untrusted package execution. Require an explicit installation and approval step instead.
  • Run the MCP process in a restricted environment with minimal filesystem access, a sanitized environment, no unnecessary credentials, and constrained outbound network access.
  • Establish an upgrade process that tests and approves each exact dependency version before changing the pin.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "📬"
    homepage: https://pipeworx.io/packs/zippopotam
---

Static analysis

No suspicious patterns detected.