T08 · Insecure Dependencies
- Location
README.md:55- Finding
Unpinned npm Package Is Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:44,README.md:39,README.md:45, andREADME.md:55
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code Snippets
SKILL.md:42-45:markdown ## Install ```bash npx quantoracle-mcptext `README.md:36-46`: ```markdown ## Install ```bash npx quantoracle-mcpOr install globally:
bash npm install -g quantoracle-mcp quantoracle-mcptext `README.md:49-57`: ```json { "mcpServers": { "quantoracle": { "command": "npx", "args": ["-y", "quantoracle-mcp"] } } }Technical Analysis
The documented installation and MCP configuration resolve
quantoracle-mcpwithout specifying an exact version or package integrity hash. Consequently, npm retrieves whichever release the registry currently associates with the package's default distribution tag.The MCP configuration is particularly sensitive because
npx -yautomatically approves installation and execution without interactive confirmation. The downloaded package executes with the privileges and environment of the MCP host process.This project contains only documentation and a configuration schema; it does not include the source of the npm package. Therefore, the package's filesystem access, network activity, wallet handling, environment-variable access, and payment behavior cannot be independently verified from the audited artifact.
This is a supply-chain weakness rather than evidence that the current npm package is malicious. Exploitation requires the package, its publisher account, the registry resolution process, or another relevant supply-chain component to be compromised.
Attack Path
- An attacker compromises the npm publisher account, package, or another part of the package publication pipeline.
- The attacker publishes a malicious version under the `quantor ...[truncated 1423 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the npm package to a reviewed exact version in every command and MCP configuration, for example:
json { "command": "npx", "args": ["--no-install", "quantoracle-mcp@2.4.1"] }The exact version must first be installed through a controlled dependency installation process.
-
Manage the package as a local project dependency rather than resolving the registry's latest release whenever the MCP server starts:
bash npm install --save-exact quantoracle-mcp@2.4.1 -
Commit and enforce a lockfile containing npm integrity metadata. Use
npm ciin automated deployments so dependency versions cannot drift silently. -
Configure the MCP client to invoke the pinned local executable from
node_modules/.binrather than permittingnpxto download missing packages automatically. -
Remove the unattended
-yinstallation behavior from long-lived MCP configurations. Fail closed if the reviewed package version is unavailable. -
Publish or vendor the relevant MCP transport source with the Skill so reviewers can verify network, wallet, filesystem, and payment behavior.
-
Run the MCP server under a dedicated least-privileged account or sandbox. Restrict filesystem access, outbound network destinations, environment variables, and wallet capabilities to the minimum required.
-
Establish an upgrade process that reviews source changes, package provenance, signatures where available, dependency changes, and integrity values before changing the pinned version.
-
