T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party Package Is Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16-17, 25-26, 91; equivalent instructions also appear inprompt_context.md:7-8, 16-17, 84,skill.toml:8-9, 17-18, 86, andREADME.md:16, 42-43
Vulnerability Type: Unpinned runtime dependency
Risk Level: MediumVulnerable Code
markdown - **`uvx`** (recommended) or `python3` with `ecovacs-robot-mcp` installedjson { "ecovacs_mcp": { "command": "uvx", "args": ["--from", "ecovacs-robot-mcp", "python", "-m", "ecovacs_robot_mcp"], "env": { "ECO_API_KEY": "YOUR_API_KEY", "ECO_API_URL": "https://open.ecovacs.com" } } }markdown - **Server won't start** — ensure `uvx` is available (`pip install uv`), or install directly: `pip install ecovacs-robot-mcp`Technical Analysis
The documented
uvxcommand resolves and executesecovacs-robot-mcpwithout an exact version constraint, integrity hash, lock file, or signed-provenance verification. The fallbackpip installcommand is similarly unpinned.As a result, the code executed during future installations can differ from the dependency version that existed when this Skill was reviewed. The downloaded MCP process also receives
ECO_API_KEYthrough its environment and is expected to interact with account-bound physical devices. The project itself contains only prompt and metadata files, so the effective runtime implementation is outside the audited artifact.This is a supply-chain exposure rather than evidence that the current external package is malicious. Describing the associated repository as official does not ensure that package resolution will always produce a previously audited artifact.
Attack Path
- An attacker compromises the package publisher, package-index account, release process, or another relevant dependency-distribution component.
- The attacker publishes a malicious or backdoored release under the package name
ecovacs-robot-mcp. - A user follows the documented ...[truncated 1172 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
ecovacs-robot-mcpto a specific, reviewed version in bothuvxand installation examples. - Verify package integrity using hashes from a committed lock file or equivalent reproducible dependency mechanism.
- Prefer signed releases and verify package provenance before execution.
- Document a controlled upgrade process that reviews dependency changes before updating the pinned version.
- Run the MCP server under a dedicated, unprivileged account or sandbox with minimal filesystem and network access.
- Use a narrowly scoped, revocable API key where the Ecovacs platform supports such restrictions.
- Avoid exposing unrelated credentials to the MCP process and ensure environment variables are not logged.
- Keep the package name, pinned version, and integrity metadata consistent across
SKILL.md,prompt_context.md,skill.toml, andREADME.md.
- Pin
