T08 · Insecure Dependencies
- Location
SKILL.md:89- Finding
Unpinned Third-Party MCP Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 89
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash pip install mcp-seedreamTechnical Analysis
The documented installation command retrieves and installs the latest available version of
mcp-seedreamwithout an exact version constraint or cryptographic hash verification. Consequently, the effective dependency code can change after this skill has been reviewed.The project does not include the package source, a lock file, integrity hashes, or other provenance controls. If a future package release or its distribution account is compromised, users following this instruction could install attacker-controlled code. Python package installation may execute build-system hooks during installation, while the installed MCP server can execute code later when invoked.
Attack Path
- An attacker compromises the package publisher account, distribution process, or another relevant software-supply-chain component.
- The attacker publishes a malicious release under the expected
mcp-seedreampackage name. - A user follows the instruction in
SKILL.mdand runspip install mcp-seedream. - Because no version or hash is pinned, pip resolves and downloads the attacker-controlled release.
- Malicious code executes during package installation or when the installed MCP server is subsequently invoked.
- The code operates with the privileges of the installing or invoking user and may access data available in that environment, potentially including
ACEDATACLOUD_API_TOKEN.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user who installs or runs the package. The accessible scope may include the user's files, environment variables, application credentials, and network access. In the documented environment, the configured AceDataCloud API token could be exposed or mis ...[truncated 184 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an exact, reviewed version, for example:
bash python -m pip install "mcp-seedream==<reviewed-version>" - Distribute a lock file or requirements file containing cryptographic hashes, and install with
--require-hashes. - Verify the package publisher, source repository, release signatures, and package provenance before recommending it.
- Review the pinned package source and repeat the review before updating the pinned version.
- Recommend installation in a dedicated virtual environment with minimal filesystem and credential access.
- Avoid installing or running the package with administrative or root privileges.
- Provide the verified source location and expected package hash so users can independently validate the downloaded artifact.
- Pin the dependency to an exact, reviewed version, for example:
