T08 · Insecure Dependencies
- Location
SKILL.md:80- Finding
Unpinned Third-Party Python Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 80
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code Snippet:
bash pip install mcp-fluxTechnical Analysis
The skill instructs users to install
mcp-fluxfrom pip's configured package index without specifying a version, cryptographic hash, trusted source repository, or integrity verification procedure. Consequently, the installed artifact can change independently of the reviewed skill content.This creates a supply-chain risk: compromise of the package, its publisher account, its dependencies, or the configured package index could cause users to install attacker-controlled code. The audit did not establish that
mcp-fluxis currently malicious; the confirmed weakness is the absence of dependency pinning and artifact verification.Attack Path
- An attacker compromises the
mcp-fluxdistribution channel, publisher account, package release process, or one of its unresolved dependencies. - The attacker publishes a malicious release under the package name expected by the documented command.
- A user follows the skill instructions and runs
pip install mcp-flux. - Pip resolves the current package and dependency versions from its configured index without checking project-provided hashes.
- Attacker-controlled code may execute during installation or later when the installed package is imported or launched.
Impact Assessment
Malicious dependency code could execute with the privileges of the user who installs or runs the package. Depending on those privileges and the local environment, the compromise could affect accessible files, environment variables, API credentials, network resources, and subsequent MCP operations. System-wide or privileged installation would increase the potential scope.
The project contains only
SKILL.md; no embedded scripts, persistence mechanisms, instruction hij ...[truncated 61 chars]- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed, exact version, such as
mcp-flux==<reviewed-version>. - Publish and verify cryptographic hashes using a requirements file and
pip install --require-hashes. - Document the package's verified official repository, publisher identity, and release provenance.
- Review and pin transitive dependencies through a lockfile or hash-locked requirements file.
- Prefer signed releases or attestations where supported, and verify them before installation.
- Recommend installation in a dedicated virtual environment or isolated container using a non-privileged account.
- Establish a periodic dependency-review process before updating the pinned version.
- Pin the dependency to a reviewed, exact version, such as
