T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned npm Packages Are Downloaded and Executed Without Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29–42
Vulnerability Type: Supply-chain risk through automatic execution of mutable third-party packages
Risk Level: MediumVulnerable Code
json { "mcpServers": { "gogcli-docs": { "command": "npx", "args": ["-y", "gogcli-mcp-docs"], "env": { "GOG_ACCOUNT": "you@example.com" } }, "gogcli-sheets": { "command": "npx", "args": ["-y", "gogcli-mcp-sheets"] } } }json { "mcpServers": { "gogcli": { "command": "npx", "args": ["-y", "gogcli-mcp"] } } }Technical Analysis
The documented configurations use
npx -yto resolve, download, and execute npm packages automatically. The package references do not specify exact versions, integrity hashes, lockfiles, or other verification controls. Consequently, the code executed by users may change after this skill has been reviewed.The executable implementations of these packages are not present in the audited artifact, which contains only
SKILL.md. Their behavior therefore cannot be independently verified from the available project content. This is an insecure dependency pattern rather than evidence that the referenced packages are currently malicious.The risk is amplified because the document states that these MCP servers use a locally authenticated
gogcliaccount. A compromised dependency would execute with the local user's process privileges and could attempt to use credentials or authorization available to that process.Attack Path
- A user adopts one of the documented MCP configurations.
- The MCP client invokes
npxwith-yand an unversioned package name. - npm resolves the package version from mutable registry metadata and downloads it without interactive confirmation.
- If the package, a transitive dependency, a maintainer account, or the distribution channel has been compromised, attacker-control ...[truncated 1005 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every npm package to an exact, reviewed version rather than relying on the latest registry resolution, for example
gogcli-mcp-docs@x.y.z. - Install dependencies through a committed lockfile and use integrity verification, such as
npm ci, in a controlled deployment step. - Avoid
npx -yfor routine server startup. Preinstall reviewed packages and invoke fixed local binaries instead of downloading executable code on demand. - Verify package provenance, registry ownership, release signatures or attestations, and published integrity metadata before installation.
- Include or link to version-matched, auditable source code and document how published artifacts are reproducibly built from that source.
- Run each MCP server in a restricted environment with only the required filesystem, network, and environment-variable access.
- Grant the Google account only the minimum OAuth scopes required for the selected Workspace API and use a dedicated account where practical.
- Keep credentials out of broadly inherited process environments and monitor Google Workspace activity for unexpected access or modifications.
- Pin every npm package to an exact, reviewed version rather than relying on the latest registry resolution, for example
