T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Third-Party Package Execution via uvx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 54 and 63
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable code snippets:
text - 命令:`uvx douyin-mcp-server`bash mcporter config add douyin-extract "uvx douyin-mcp-server"Technical Analysis
The Skill instructs users to resolve and execute the third-party
douyin-mcp-serverpackage throughuvxwithout specifying an exact version, lockfile, package hash, or other integrity control. The project also provides no bundled implementation or canonical source reference that would allow the executed package to be matched to reviewed code.Because dependency resolution occurs when the command is invoked, the effective code can change independently of this Skill. A compromised package account, malicious release, package-name takeover, or dependency confusion event could therefore cause attacker-controlled code to execute with the privileges of the user running the MCP server.
Attack Path
- An attacker compromises, replaces, or publishes a malicious release under the package identity resolved as
douyin-mcp-server. - A user follows the documented configuration and registers
uvx douyin-mcp-serveras thedouyin-extractMCP command. - The MCP integration invokes that command during Skill use.
uvxresolves and executes the mutable third-party package.- Malicious package code runs with the Agent user's privileges and can access resources available to that account.
Impact Assessment
Successful exploitation provides arbitrary code execution within the security context of the user running the MCP service. Depending on that user's permissions, an attacker could read or modify local files, inspect browser-related data, access the persisted Douyin authentication cookie documented at
~/douyin-mcp-server/mcp-server/douyin-cookies.json, impersonate the authenticated account, o ...[truncated 144 chars]- An attacker compromises, replaces, or publishes a malicious release under the package identity resolved as
- Remediation
View remediation
Remediation Suggestions
- Pin
douyin-mcp-serverto a specific, audited version rather than resolving an unconstrained current release. - Use a locked dependency manifest with cryptographic hashes and require integrity verification before execution.
- Document the canonical package repository, publisher identity, and expected package checksum.
- Review the package and its transitive dependencies before deployment, and repeat the review before version upgrades.
- Install dependencies during a controlled provisioning step instead of dynamically resolving mutable packages during routine Skill execution.
- Run the MCP server in an isolated, least-privilege environment with narrowly scoped filesystem and network access.
- Store Douyin cookies with owner-only permissions, prevent cookie values from entering logs, and keep them outside directories accessible to the dependency unless access is operationally required.
- Pin
