T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Third-Party Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 54-62
Vulnerability Type: Supply-chain exposure caused by unpinned package execution
Risk Level: MediumVulnerable Code
json { "mcpServers": { "rentaunhumano": { "command": "npx", "args": ["-y", "@rentaunhumano/mcp-server"], "env": { "RENTA_API_URL": "https://rentaunhumano.com", "RENTA_API_KEY": "${RENTA_API_KEY}" } } } }Technical Analysis
The configuration invokes
npx -ywith@rentaunhumano/mcp-serverbut does not specify an exact package version or verify package integrity. If the package is unavailable locally,npxcan retrieve it from the configured npm registry and execute it. The-yoption suppresses the normal installation confirmation.Consequently, the code executed by this configuration can change after the Skill has been reviewed. Compromise of the package publisher, registry account, package release process, or dependency chain could cause a malicious release to execute on users' systems. The MCP server also receives
RENTA_API_KEYin its environment, making that credential accessible to the downloaded process.This finding establishes an unsafe dependency-execution pattern; it does not establish that the currently published package is malicious.
Attack Path
- An attacker compromises the npm package publisher, release pipeline, registry account, or a dependency used by
@rentaunhumano/mcp-server. - The attacker publishes a malicious version that can be selected by the unversioned package reference.
- A user applies the documented configuration and starts the MCP server.
npx -ydownloads the selected package without an interactive confirmation and executes it locally.- The malicious process reads
RENTA_API_KEYfrom its environment and may access MCP requests, mission details, or other resources available under the invoking user ...[truncated 958 chars]
- An attacker compromises the npm package publisher, release pipeline, registry account, or a dependency used by
- Remediation
View remediation
Remediation Suggestions
- Pin the package to an audited exact version, for example
@rentaunhumano/mcp-server@X.Y.Z, rather than resolving the latest compatible release. - Install dependencies through a committed lockfile and use a reproducible installation mechanism such as
npm ci. - Verify package integrity and provenance using registry integrity metadata, signed provenance attestations, and trusted publisher information.
- Avoid automatic confirmation for first-time package retrieval. Remove
-ywhere practical so unexpected installation is visible. - Review and monitor both the MCP package and its transitive dependencies for ownership changes, unexpected releases, and known vulnerabilities.
- Run the MCP server in a restricted environment with minimal filesystem access, limited outbound networking, and only the required environment variables.
- Use a narrowly scoped, revocable API key. Keep sandbox and production credentials separate, rotate exposed credentials promptly, and monitor API activity for misuse.
- Prefer a locally installed, verified executable over downloading executable code during each invocation.
- Pin the package to an audited exact version, for example
