T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Unpinned Third-Party Source Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 22–35
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: MediumVulnerable Code
bash If the project does not already include MCP Sentinel, clone and build it: git clone https://github.com/fasjdas/mcp-sentinel cd mcp-sentinel npm install npm run build Run an audit: node dist/cli.js audit /path/to/projectTechnical Analysis
The skill instructs the agent to clone the current default branch of an external GitHub repository, install its npm dependency graph, run its build process, and execute the resulting CLI. Neither an immutable commit nor a cryptographically verified release is specified.
The effective code executed by these commands can therefore change after the skill has been reviewed. In addition,
npm installmay execute package lifecycle scripts from the repository or its transitive dependencies. A compromise of the upstream repository, an unsafe dependency update, or a malicious npm lifecycle script could result in arbitrary local code execution under the invoking user's account.The external repository and its dependencies are not included in this artifact, so their behavior cannot be validated by this audit.
Attack Path
- An attacker compromises the upstream repository, its default branch, or one of its npm dependencies.
- The attacker introduces malicious code into a source file, build script, or npm lifecycle script.
- An agent follows the documented workflow and clones the mutable upstream repository.
npm installexecutes a malicious lifecycle script, ornpm run buildincorporates the malicious source into the generated CLI.- The agent runs
node dist/cli.js audit /path/to/project. - The malicious code executes with the permissions of the invoking user and can access resources available in that execution environment.
Impact Assessment
Successful exploitation could provide arbitrary command execu ...[truncated 598 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the external repository to a reviewed immutable commit hash or a signed release tag.
- Publish and verify a cryptographic checksum or signature before executing downloaded code.
- Require a committed and reviewed lockfile, and use
npm cirather thannpm installto prevent unreviewed dependency resolution changes. - Disable dependency lifecycle scripts where feasible, such as with
npm ci --ignore-scripts, and explicitly run only reviewed build steps. - Vendor the reviewed scanner source or distribute a reproducible, signed artifact instead of cloning a mutable default branch.
- Run the scanner in a sandbox or container with:
- Read-only access to the narrowest required project directory.
- No access to unrelated home-directory files or credential stores.
- No unnecessary network access.
- A non-privileged user account.
- Review dependency provenance and use automated dependency and integrity verification before installation.
- Document the exact trusted version, commit, lockfile checksum, and verification procedure in
SKILL.md.
