T08 · Insecure Dependencies
- Location
SKILL.md:32- Finding
Unpinned Third-Party Package Download and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is transparent about being a residential-proxy MCP tool, but it promotes anti-bot bypass and includes unpinned npx install commands that would run third-party code with proxy credentials.
Review before installing. Only use this with sites and proxy providers you are authorized to access, avoid sending sensitive URLs or data through the proxy, and prefer a pinned or verified install command such as the reviewed package version rather than the unpinned npx examples.
SKILL.md:32Unpinned Third-Party Package Download and Execution
The metadata description explicitly advertises bypassing anti-bot protections and geo-targeting through residential proxies, which meaningfully increases misuse risk. In the context of an agent skill, this normalizes evasion behavior and can facilitate scraping or access patterns that circumvent site defenses and accountability controls.
The main description again instructs users to route requests through residential devices to bypass anti-bot systems, and this is reinforced by later examples like Cloudflare-protected targets. In context, the skill is not merely describing neutral networking behavior; it is actively steering agent operators toward evasion of defensive mechanisms, which makes harmful use more likely.
The skill instructs users to launch an MCP server via npx -y bestproxy4agents without pinning an exact package version. This allows a future package update, compromised maintainer account, or dependency hijack to change the code executed at install/runtime, creating a supply-chain execution risk on the user's machine or agent host.
This is the same unpinned npx execution pattern repeated in a second setup path, so users following either path may execute whatever package version is current at the time. Because npx fetches and runs code, an attacker who gains control of publishing or dependency resolution could achieve arbitrary code execution in the MCP environment.
No suspicious patterns detected.