T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unverified Global Installation of a Third-Party Executable
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–17
Vulnerability Type: Third-party dependency and supply-chain risk
Risk Level: Mediumyaml bins: - npm install: command: npm args: - install - -g - "ppspy-mcp-server@1.0.1"Technical Analysis
The skill instructs npm to install
ppspy-mcp-server@1.0.1globally and subsequently relies on the resulting executable. Although the package version is pinned, the project provides neither the dependency source nor an integrity digest with which to authenticate the downloaded artifact.Pinning a version prevents ordinary automatic upgrades, but it does not protect against compromise of the npm publisher account, package contents, package registry, configured registry endpoint, or distribution infrastructure. npm installation may also execute package lifecycle scripts. Such scripts can run during installation before the MCP server itself is invoked.
The global
-ginstallation increases exposure by placing the package in a shared executable or module location rather than an isolated project environment. The reviewed project contains no lockfile, vendored source, checksum verification, lifecycle-script restriction, sandbox configuration, or other mechanism that permits the installed code to be independently verified.Attack Path
- An attacker compromises the package publisher, npm distribution path, or the registry configured on the host.
- The attacker causes malicious content or lifecycle scripts to be served for the referenced package.
- Installation of the skill runs
npm install -g ppspy-mcp-server@1.0.1. - Malicious npm lifecycle code executes with the permissions of the user performing the installation, or the globally installed executable is replaced with attacker-controlled logic.
- When the MCP server is launched, the executable receives access to
PPSPY_API_KEYthrou ...[truncated 1008 chars]
- Remediation
View remediation
Remediation Suggestions
- Avoid global installation. Install the server into a dedicated project directory or isolated container under an unprivileged service account.
- Vendor and audit the exact server source, or obtain it from a trusted internal registry after security review.
- Generate and retain a lockfile containing registry-resolved integrity metadata, and enforce reproducible installation with
npm ci. - Verify package provenance, publisher identity, signatures or attestations, and cryptographic artifact hashes before execution.
- Disable npm lifecycle scripts during installation with
--ignore-scriptswhere compatible. If lifecycle scripts are required, review and explicitly allow them. - Run the MCP server in a sandbox with minimal filesystem access, restricted process execution, and outbound network access limited to required PPSPY endpoints.
- Use a narrowly scoped, revocable API key with usage and billing limits. Do not expose unrelated environment variables to the server.
- Monitor dependency advisories, package ownership changes, integrity failures, API-key usage, and unexpected outbound connections.
- Document a trusted package-update process that requires source review and integrity verification before changing the pinned version.
