T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Globally Installed Third-Party MCP Server Executes with API Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10-20
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumyaml install: command: npm args: - install - -g - "ppspy-mcp-server@1.0.1" primaryEnv: PPSPY_API_KEY emoji: "🔍" homepage: https://www.ppspy.com mcpServers: ppspy: command: ppspy-mcp-server env: PPSPY_API_KEY: "{{PPSPY_API_KEY}}"Technical Analysis
The skill installs
ppspy-mcp-server@1.0.1from the npm registry using the global-goption and subsequently executes the installed command withPPSPY_API_KEYin its environment.Pinning the direct package version reduces version drift, but the project does not provide a lockfile, integrity hash, vendored source, verified publisher information, or other mechanism through which the package and its transitive dependencies can be audited from this repository. npm lifecycle scripts may also execute during installation. The global installation scope gives package installation behavior access to user-level global npm locations beyond a project-local directory.
The inspected repository contains only
SKILL.md; therefore, this finding does not establish that the referenced package is malicious. It identifies a supply-chain trust boundary in which externally retrieved and unaudited code is installed and executed with access to a credential.Attack Path
- A user installs or enables the skill.
- The installation process retrieves
ppspy-mcp-server@1.0.1and its transitive dependencies from npm. - npm executes any permitted package lifecycle scripts and places package files in the global npm installation location.
- The framework launches the globally installed
ppspy-mcp-serverexecutable. - The process receives
PPSPY_API_KEYthrough its environment. - If the package, publisher account, registry response, or a transitive dependency has been compromised, attack ...[truncated 695 chars]
- Remediation
View remediation
Remediation Suggestions
- Install the server in an isolated, project-local environment rather than using
npm install -g. - Vendor or independently audit the exact package source and all transitive dependencies before deployment.
- Use a lockfile and verify registry integrity hashes or package signatures against trusted, reviewed values.
- Disable npm lifecycle scripts during installation where operationally possible, or explicitly review every required script before allowing execution.
- Run the MCP server in a sandbox with restricted filesystem access, outbound network access, and operating-system privileges.
- Supply a narrowly scoped, revocable PPSPY API key with minimal quota and billing permissions; rotate it if package compromise is suspected.
- Monitor package provenance and publisher ownership, and establish a controlled update process rather than retrieving dependencies directly in production.
- Install the server in an isolated, project-local environment rather than using
