T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 35–42
Vulnerability Type: Supply-chain risk caused by an unpinned third-party package
Risk Level: MediumVulnerable Code
json { "mcpServers": { "dynamics-partner-advisor": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-sse", "https://topdynamicspartners.com/api/mcp/sse"] } } }Technical Analysis
The documented MCP configuration runs
@modelcontextprotocol/server-ssethroughnpxwithout specifying an exact package version or verifying package integrity. The-yoption automatically approves installation, so users following the instructions may retrieve and execute whichever package release the registry resolves at that time.Consequently, the locally executed code can change after this skill has been reviewed. A compromised package, maintainer account, publication pipeline, or package registry could cause malicious lifecycle or runtime code to execute with the privileges of the user running the MCP client.
This finding establishes an insecure dependency configuration. It does not establish that the package or hosted endpoint is currently malicious.
Attack Path
- An attacker compromises the package maintainer account, package publication pipeline, or upstream registry distribution path.
- The attacker publishes a malicious release under the referenced package name.
- A user copies the configuration from
SKILL.mdand starts the MCP client. npx -yresolves and downloads the unpinned package without interactive approval.- Package lifecycle or runtime code executes locally under the MCP client user's account.
- The malicious code can access resources available to that account and interfere with MCP communications.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user who launches the MCP client. Depending on that user's environment, the compromised pa ...[truncated 400 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@modelcontextprotocol/server-sseto a reviewed, exact version rather than relying on registry resolution of the latest release. - Install the dependency through a package manifest and committed lockfile so that the complete dependency graph is reproducible.
- Verify package integrity using the package manager's supported integrity metadata and a trusted registry.
- Avoid automatic installation approval with
npx -ywhere practical; require an explicit installation or review step. - Document the expected publisher, exact version, package source, and checksum so users can validate provenance.
- Run the MCP process with least privilege in an isolated environment, without unnecessary filesystem access, environment secrets, or credentials.
- Establish a controlled dependency-update process that reviews package changes before advancing the pinned version.
- Pin
