T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Global Installation and Execution of an Unverified Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–23
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumyaml bins: - npm install: command: npm args: - install - -g - "ppspy-mcp-server@1.0.1" primaryEnv: PPSPY_API_KEY emoji: "🔍" homepage: https://www.ppspy.com mcpServers: ppspy: command: ppspy-mcp-server env: PPSPY_API_KEY: "{{PPSPY_API_KEY}}"Technical Analysis
The Skill directs the host to install
ppspy-mcp-server@1.0.1globally from the npm registry and subsequently execute its binary with access toPPSPY_API_KEY.Pinning the dependency to version
1.0.1provides some reproducibility, but the configuration does not verify the package with a trusted integrity hash, lockfile, signature, or vendored source review. npm installation can also execute package lifecycle scripts. The global-ginstallation modifies the host-wide npm environment rather than an isolated project environment.The package implementation is not included in the audited project, so its installation-time and runtime behavior cannot be verified from the supplied artifact. If the package version or its publication process is compromised, attacker-controlled code could execute under the privileges of the user running the Skill and receive the configured API credential.
Attack Path
- An attacker compromises the npm publisher account, registry delivery path, or package contents associated with
ppspy-mcp-server@1.0.1. - The Skill invokes
npm install -g ppspy-mcp-server@1.0.1. - Malicious package lifecycle scripts may execute during installation, or malicious logic may be installed in the
ppspy-mcp-serverbinary. - The host launches the installed binary as an MCP server.
- The process receives
PPSPY_API_KEYthrough its environment. - Attacker-controlled code can read or exfiltrate that credential and access files, network r ...[truncated 865 chars]
- An attacker compromises the npm publisher account, registry delivery path, or package contents associated with
- Remediation
View remediation
Remediation Suggestions
- Vendor and independently audit the MCP server source before deployment.
- Install the dependency into a dedicated, non-global project directory or isolated container instead of using
npm install -g. - Use a lockfile and verify the package archive against a trusted integrity hash or signed provenance.
- Disable npm lifecycle scripts during installation where the package does not require them, such as with
--ignore-scripts. - Run the MCP server under a dedicated, unprivileged operating-system account with restricted filesystem and network access.
- Pass only
PPSPY_API_KEYto the process rather than inheriting the full parent environment. - Use a narrowly scoped API key where supported, monitor its usage, and establish rotation and revocation procedures.
- Pin and validate the runtime executable path so an unrelated binary with the same name cannot be selected through
PATH. - Re-audit package source and transitive dependencies before upgrades or deployment.
