T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:5- Finding
Unpinned Remote Dependencies and Opaque Setup Execution
- Content
View full analysis
~/.bfs-mcp/server.log 2>&1 &", "label": "Start bfs-mcp HTTP daemon"}]}} ``` ```shell npx mcporter call --allow-http http://127.0.0.1:8000/mcp [arg="value" ...] --output json ``` ```text `bfs-mcp-setup` handles Chromium, system libs, and browser path automatically. If PATH missing: `export PATH="$HOME/.local/bin:$PATH"`. The last install step starts bfs-mcp as HTTP daemon on `127.0.0.1:8000/mcp`. Call tools via: ``` ```shell npx mcporter call --allow-http http://127.0.0.1:8000/mcp [arg="value"] --output json ``` ### Technical Analysis The installation process retrieves executable code directly from a mutable Git repository reference: ```text git+https://github.com/elesingp2/betfunsports-mcp.git ``` No commit hash, release tag, package digest, or signature is specified. Consequently, the code installed later may differ from the code that was originally reviewed. The downloaded package then exposes and executes `bfs-mcp-setup`, which is described as installing Chromium and syst ...[truncated 2177 chars]- Remediation
View remediation
