T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–27
Vulnerability Type: Unpinned third-party package execution
Risk Level: HighVulnerable Code
json { "mcpServers": { "gogcli-classroom": { "command": "npx", "args": ["-y", "gogcli-mcp-classroom"], "env": { "GOG_ACCOUNT": "you@gmail.com" } } } }Technical Analysis
The MCP configuration runs
npx -y gogcli-mcp-classroomwithout specifying an exact package version or validating package integrity. Consequently,npxcan retrieve and execute whichever release the npm registry resolves at invocation time. The-yoption suppresses the normal installation confirmation.This creates a supply-chain boundary in which the code executed by the skill can change after the skill itself has been reviewed. If the package, publisher account, registry response, or upstream release process is compromised, a malicious package version could execute locally under the user's account. No malicious payload is embedded in the reviewed project; the vulnerability arises from trusting mutable remote dependency content.
Attack Path
- An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component for
gogcli-mcp-classroom. - The attacker publishes a malicious release that is selected by npm as the current version.
- A user starts the documented MCP server configuration.
npx -yretrieves the package without requesting confirmation and executes its entry point.- The malicious process runs with the invoking user's local privileges and can access environment data and credentials available to that process.
- Where authenticated Google Classroom access is available, the process could misuse the permissions granted to the associated account.
Impact Assessment
Successful exploitation permits arbitrary package code execution wit ...[truncated 541 chars]
- An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component for
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an exact reviewed version, for example
gogcli-mcp-classroom@X.Y.Z, rather than resolving the latest release. - Install dependencies through a committed lockfile and use a deterministic installation method such as
npm ci. - Verify registry integrity metadata and package provenance before installation.
- Remove automatic
-yapproval where interactive confirmation is operationally feasible. - Prefer installing and reviewing the dependency separately instead of downloading executable code whenever the MCP server starts.
- Monitor the package and its transitive dependencies for ownership changes, unexpected releases, and known vulnerabilities.
- Grant only the minimum Google OAuth scopes and Classroom permissions required for the intended operation.
- Run the MCP server in a restricted environment with limited filesystem, environment-variable, credential, and network access.
- Pin the dependency to an exact reviewed version, for example
