T08 · Insecure Dependencies
- Location
scripts/extract.sh:96- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
scripts/extract.sh:96
Vulnerability Type: Unpinned dynamically retrieved dependency
Risk Level: HighVulnerable Code:
bash npx -y mcp-remote https://mcp.tavily.com/mcp </dev/null >/dev/null 2>&1 &Technical Analysis
When no Tavily credential is available, the script invokes
npx -y mcp-remote. The-yoption suppresses the package-installation confirmation, while the absence of an exact package version or integrity constraint causes npm to resolve mutable package content at execution time.Consequently, the code executed during a future invocation is not necessarily the code that was available when the skill was audited. If the npm package, its maintainer account, the relevant registry infrastructure, or a transitive dependency is compromised, attacker-controlled JavaScript can execute locally. This is a supply-chain risk rather than evidence that the current package is malicious.
Attack Path
- An attacker compromises the
mcp-remotenpm package, its publication account, registry resolution, or one of its dependencies. - The attacker publishes a malicious version that is selected by the unversioned package reference.
- A user invokes
scripts/extract.shwithoutTAVILY_API_KEYand without a usable cached Tavily token. - Execution enters the OAuth branch at lines 92–119.
npx -ydownloads the currently resolved package without interactive approval or an integrity check.- The package executes with the same operating-system identity and environment as the user running the skill.
- Malicious package code can access resources available to that user before continuing, disrupting, or impersonating the expected OAuth process.
Impact Assessment
Successful exploitation permits arbitrary code execution with the privileges of the invoking user. The affected scope can include readable local files, environment variables, ...[truncated 324 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace the unversioned package invocation with an exact, reviewed version rather than allowing npm to resolve the latest release.
- Commit and enforce a lockfile with integrity metadata for the package and all transitive dependencies.
- Prefer installing dependencies during a controlled build or installation phase instead of downloading executable code during normal skill execution.
- Consider bundling a reviewed OAuth client implementation with the skill so that runtime behavior cannot change independently of the audited artifact.
- Verify package provenance and signatures where supported, and use a trusted registry configured to reject unexpected sources.
- Remove automatic confirmation via
-y, or require explicit informed user consent before any runtime package installation. - Run the OAuth helper with minimal filesystem, environment, credential, and network access where sandboxing is available.
- Fail closed and display a clear manual authentication procedure if the pinned and integrity-verified helper is unavailable.
