T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unreviewable Globally Installed Third-Party MCP Server
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–20
Vulnerability Type: Third-party supply-chain exposure through global npm installation
Risk Level: MediumVulnerable Configuration:
yaml bins: - npm install: command: npm args: - install - -g - "pipiads-mcp-server@1.0.3" primaryEnv: PIPIADS_API_KEY emoji: "📊" homepage: https://www.pipiads.com mcpServers: pipiads: command: pipiads-mcp-server env: PIPIADS_API_KEY: "{{PIPIADS_API_KEY}}"Technical Analysis
The skill globally installs and executes the external npm package
pipiads-mcp-server@1.0.3. The package's source code, dependency lockfile, integrity hash, and security provenance are not included in the audited project, so its installation scripts, transitive dependencies, and runtime behavior cannot be verified from the available artifact.Pinning the version improves reproducibility but does not authenticate the downloaded package or its transitive dependencies. npm installation can also execute package lifecycle scripts. The resulting MCP server is then supplied with
PIPIADS_API_KEY, placing a sensitive API credential within reach of all code loaded by the package.There is no evidence in the reviewed file that this package is malicious. The risk arises from executing an externally retrieved, unreviewable dependency with access to a secret and from installing it globally rather than in an isolated project environment.
Attack Path
- A user or agent installs the skill.
- The installation command downloads
pipiads-mcp-server@1.0.3and its transitive dependencies from the configured npm registry. - npm executes any enabled installation lifecycle scripts with the installer user's privileges.
- The globally installed
pipiads-mcp-serverexecutable is invoked as an MCP server. - The process receives
PIPIADS_API_KEYthrough its environment. - If the packa ...[truncated 867 chars]
- Remediation
View remediation
Remediation Suggestions
- Avoid global installation. Install the MCP server in a dedicated, non-privileged project directory or isolated container.
- Include an auditable lockfile and verify package and dependency integrity using trusted registry metadata and cryptographic hashes.
- Review the package source, published artifact, maintainers, lifecycle scripts, and complete transitive dependency tree before deployment.
- Disable npm lifecycle scripts during installation where they are not required, for example by using an appropriately controlled
ignore-scriptspolicy. - Execute the MCP server under a sandboxed, least-privileged account with restricted filesystem and network access.
- Supply a narrowly scoped, revocable API key and rotate it promptly if package integrity is ever questioned.
- Prefer a locally reviewed and vendored implementation or a signed release obtained from a verified publisher.
