Back to skill

Security audit

Eth Labels

Security checks for vulnerabilities and agentic risk

Overview

The skill's crypto lookup purpose is coherent, but its setup asks users to run mutable external GitHub and npm code that was not included in the reviewed artifact.

Review the upstream repository before installing, pin it to a known commit or release, prefer locked dependencies and local binaries over unpinned npx, and run the MCP server with only the permissions and environment variables it needs. The artifact does not show malicious behavior, but the install path deserves caution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned External Repository and npm Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19-25, SKILL.md:43-45, and SKILL.md:49-53
Vulnerability Type: Unpinned third-party code and package execution
Risk Level: Medium

The documented installation process retrieves and executes code from a mutable Git repository and invokes an npm package without pinning reviewed versions.

Relevant code from SKILL.md:19-25:

bash
git clone https://github.com/dawsbot/eth-labels.git
cd eth-labels/mcp
npm install
npm run build

Relevant code from SKILL.md:43-45:

bash
cd eth-labels/mcp
npx tsx index.ts

Relevant code from SKILL.md:49-53:

json
{
  "mcpServers": {
    "eth-labels": {
      "command": "npx",
      "args": ["tsx", "/path/to/eth-labels/mcp/index.ts"]
    }
  }
}

Technical Analysis

git clone retrieves the repository's current default branch rather than a specific reviewed commit or signed release. Its effective contents can therefore change after this skill has been audited. The subsequent npm install may execute dependency lifecycle scripts, while npm run build executes a repository-defined script.

The alternative setup also runs npx tsx without an exact package version. Depending on the local environment and npm behavior, npx can download and execute a package that was not present when the skill documentation was reviewed.

The external repository, package manifests, lockfile, dependency graph, and lifecycle scripts are not included in the audited artifact. Their implementation and integrity therefore cannot be verified from this project. This is a supply-chain weakness rather than evidence that the referenced repository or package is currently malicious.

Attack Path

  1. An attacker compromises the upstream GitHub repository, one of its npm dependencies, or the package distribution account used for tsx.
  2. The attacker publishes code containing a malicious lif ...[truncated 1256 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the external repository to a specific reviewed commit hash or cryptographically signed release tag:
    bash
    git clone https://github.com/dawsbot/eth-labels.git
    cd eth-labels
    git checkout --detach VERIFIED_COMMIT_HASH
    
  2. Publish the expected commit hash and release checksum through a trusted channel, and require users to verify them before running installation commands.
  3. Include and review a dependency lockfile, then replace npm install with npm ci so dependency resolution matches the audited versions.
  4. Pin tsx to an exact reviewed version rather than invoking the unversioned package through npx.
  5. Review all direct and transitive dependencies, npm lifecycle scripts, and repository-defined build scripts before execution.
  6. Where feasible, disable lifecycle scripts during dependency installation and run only explicitly reviewed build steps.
  7. Prefer a versioned, signed release artifact or locally audited installation package over executing a mutable upstream branch.
  8. Run the MCP server with least privilege in an isolated account or container, exposing only the files, environment variables, and network destinations required for its stated functionality.
  9. Document how users can remove or disable the MCP configuration promptly if upstream compromise is suspected.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run the MCP server via npx tsx without pinning an exact package version, which can cause execution of whatever version is currently resolved from the registry. If the package, dependency chain, or resolution path is compromised, users may execute unintended code during setup or use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.