T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned External Repository and npm Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:19-25,SKILL.md:43-45, andSKILL.md:49-53
Vulnerability Type: Unpinned third-party code and package execution
Risk Level: MediumThe documented installation process retrieves and executes code from a mutable Git repository and invokes an npm package without pinning reviewed versions.
Relevant code from
SKILL.md:19-25:bash git clone https://github.com/dawsbot/eth-labels.git cd eth-labels/mcp npm install npm run buildRelevant code from
SKILL.md:43-45:bash cd eth-labels/mcp npx tsx index.tsRelevant code from
SKILL.md:49-53:json { "mcpServers": { "eth-labels": { "command": "npx", "args": ["tsx", "/path/to/eth-labels/mcp/index.ts"] } } }Technical Analysis
git cloneretrieves the repository's current default branch rather than a specific reviewed commit or signed release. Its effective contents can therefore change after this skill has been audited. The subsequentnpm installmay execute dependency lifecycle scripts, whilenpm run buildexecutes a repository-defined script.The alternative setup also runs
npx tsxwithout an exact package version. Depending on the local environment and npm behavior,npxcan download and execute a package that was not present when the skill documentation was reviewed.The external repository, package manifests, lockfile, dependency graph, and lifecycle scripts are not included in the audited artifact. Their implementation and integrity therefore cannot be verified from this project. This is a supply-chain weakness rather than evidence that the referenced repository or package is currently malicious.
Attack Path
- An attacker compromises the upstream GitHub repository, one of its npm dependencies, or the package distribution account used for
tsx. - The attacker publishes code containing a malicious lif ...[truncated 1256 chars]
- An attacker compromises the upstream GitHub repository, one of its npm dependencies, or the package distribution account used for
- Remediation
View remediation
Remediation Suggestions
- Pin the external repository to a specific reviewed commit hash or cryptographically signed release tag:
bash git clone https://github.com/dawsbot/eth-labels.git cd eth-labels git checkout --detach VERIFIED_COMMIT_HASH - Publish the expected commit hash and release checksum through a trusted channel, and require users to verify them before running installation commands.
- Include and review a dependency lockfile, then replace
npm installwithnpm ciso dependency resolution matches the audited versions. - Pin
tsxto an exact reviewed version rather than invoking the unversioned package throughnpx. - Review all direct and transitive dependencies, npm lifecycle scripts, and repository-defined build scripts before execution.
- Where feasible, disable lifecycle scripts during dependency installation and run only explicitly reviewed build steps.
- Prefer a versioned, signed release artifact or locally audited installation package over executing a mutable upstream branch.
- Run the MCP server with least privilege in an isolated account or container, exposing only the files, environment variables, and network destinations required for its stated functionality.
- Document how users can remove or disable the MCP configuration promptly if upstream compromise is suspected.
- Pin the external repository to a specific reviewed commit hash or cryptographically signed release tag:
