T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Globally Installed Third-Party Dependency Receives an API Credential
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12–25
Vulnerability Type: Third-party dependency and supply-chain exposure
Risk Level: MediumComplete Code Snippet:
yaml install: command: npm args: - install - -g - "ppspy-mcp-server@1.0.1" primaryEnv: PPSPY_API_KEY emoji: "🔍" homepage: https://www.ppspy.com mcpServers: ppspy: command: ppspy-mcp-server env: PPSPY_API_KEY: "{{PPSPY_API_KEY}}"Technical Analysis
The Skill installs
ppspy-mcp-server@1.0.1globally from the npm registry and then executes the installed binary withPPSPY_API_KEYin its environment. The dependency's source code is not included in the audited project, and the configuration does not specify an expected package integrity hash or another mechanism for verifying the downloaded artifact.Pinning the package version limits unintentional version changes but does not independently authenticate the artifact. npm installation can also execute package lifecycle scripts. Consequently, a compromised package release, registry account, or package-distribution path could execute code during installation or when the MCP server starts.
The global
-ginstallation increases the dependency's system-wide footprint compared with a project-local installation. There is no direct evidence in the reviewed file thatppspy-mcp-server@1.0.1is malicious; the vulnerability is the unverified trust placed in an externally distributed executable that is subsequently given a sensitive credential.Attack Path
- An attacker compromises the relevant npm publisher account, registry artifact, or another part of the package distribution chain.
- The victim activates the Skill, causing
npm install -g ppspy-mcp-server@1.0.1to retrieve and install the affected package. - Malicious npm lifecycle code may execute during installation under the privileges of ...[truncated 1098 chars]
- Remediation
View remediation
Remediation Suggestions
- Avoid global installation. Install the dependency in a project-local, isolated environment with minimal filesystem and network permissions.
- Vendor and review the MCP server source, or obtain it from a trusted, auditable source before execution.
- Use a lockfile containing npm integrity metadata and validate the expected artifact hash before installation.
- Disable npm lifecycle scripts during installation with
--ignore-scriptswhen the package supports operation without them. - Run the MCP server in a sandbox or container with access only to the resources required for PPSPY queries.
- Supply a narrowly scoped, revocable API key and document credential rotation and revocation procedures.
- Monitor API usage and billing for unexpected requests or credit consumption.
- Review the exact published contents and lifecycle scripts of
ppspy-mcp-server@1.0.1before approving deployment.
