T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23–24
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
json "command": "npx", "args": ["-y", "gogcli-mcp-drive"],Technical Analysis
The documented MCP configuration uses
npx -yto download and executegogcli-mcp-drivewithout pinning an exact package version. The-yoption suppresses the installation confirmation, while omission of a version allows the package registry to select the currently resolved release whenever the configuration is used.Consequently, the code reviewed during one installation may differ from the code executed later. If the package publisher account, npm package, release pipeline, or another relevant supply-chain component is compromised, a malicious release could be delivered automatically. The documentation identifies
github.com/chrischall/gogcli-mcpas the source while executing a separately named registry package, so users must independently verify that the registry package is controlled by the expected publisher and corresponds to the reviewed source.Attack Path
- An attacker compromises the npm package, its publisher account, or its release process.
- The attacker publishes a malicious version under the
gogcli-mcp-drivepackage name. - A user starts the documented MCP configuration.
npx -y gogcli-mcp-driveresolves, downloads, and executes the malicious release without an interactive confirmation.- The package executes with the operating-system privileges of the MCP host process.
- Because the documented prerequisites include an authenticated
gogcliinstallation and the configuration suppliesGOG_ACCOUNT, malicious code may attempt to access locally available authentication material or perform Google Drive operations through the authenticated environment. - The attacker can then act within the permissions available to the local pr ...[truncated 891 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the package to an exact, reviewed version, for example:
json "command": "npx", "args": ["-y", "gogcli-mcp-drive@X.Y.Z"]Replace
X.Y.Zwith a version whose source and published artifact have been reviewed. -
Prefer a controlled installation process using a lockfile and npm integrity metadata rather than downloading the package dynamically whenever the MCP server starts.
-
Verify that the npm package publisher, package repository metadata, and referenced GitHub repository belong to the expected maintainers. Confirm that the published artifact is reproducibly derived from the reviewed source.
-
Use dependency scanning and monitor package ownership, release-signing information, and unexpected changes in transitive dependencies.
-
Run the MCP server in a restricted environment with minimal filesystem access, limited environment variables, outbound-network controls where practical, and no unrelated credentials.
-
Grant only the Google OAuth scopes required for the intended Drive operations. Use a dedicated account where feasible and regularly review active tokens, file permissions, and shared-drive access.
-
Remove automatic confirmation suppression where operationally practical so unexpected installation activity is visible to the user.
-
