T08 · Insecure Dependencies
- Location
SKILL.md:557- Finding
Unpinned Third-Party MCP Server Is Installed Directly from a Mutable Repository
- Content
View full analysis
- Remediation
View remediation
``` 2. Verify the checked-out commit against a trusted digest or a cryptographically signed release before installation. 3. Prefer an immutable, versioned release artifact with published SHA-256 hashes. If installing dependencies from a lock file, require exact versions and hashes. 4. Review the pinned repository's packaging metadata, build backend, installation hooks, runtime network destinations, and transitive dependencies before recommending execution. 5. Install and run the component in an isolated environment with minimum privileges. Do not run installation commands as root or with `sudo`. 6. Restrict credential exposure: - Supply Apple tokens only when MusicKit functionality is explicitly requested. - Store tokens using an operating-system credential store rather than plaintext files or environment-wide configuration. - Avoid exposing the `.p8` private key to the MCP runtime if only a generated developer token is required. - Revoke and rotate tokens if an installed version is later found to be compromised. 7. Clearly label the MCP server as an optional, externally maintained component that is outside the audited Skill package, rather than presenting direct installation from the default branch as the easy path. ]]>
