T08 · Insecure Dependencies
- Location
README.md:133- Finding
Unpinned npm Package Is Downloaded and Executed via npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 133–147
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Mediumbash claude mcp add llm-knowledge-bases -- \ npx -y --package @harrylabs/llm-knowledge-bases@latest \ llm-knowledge-bases-mcp \ --vault-root /absolute/path/to/your/obsidian-vaultFor other MCP-capable agents:
bash npx -y --package @harrylabs/llm-knowledge-bases@latest \ llm-knowledge-bases-configs --vault-root /absolute/path/to/your/obsidian-vaultTechnical Analysis
The documented installation commands use
npx -yto download and execute@harrylabs/llm-knowledge-bases@latest. Thelatestnpm tag is mutable and does not identify a fixed, previously reviewed artifact. The-yoption also suppresses the normal installation confirmation.Consequently, the effective executable code can change after this Skill has been reviewed. This repository does not include the npm runtime implementation, pin an exact runtime version, provide a lockfile, or specify an integrity digest that would allow users to verify the downloaded package.
The package name is consistent with the declared product and there is no evidence in the audited repository that the current package is malicious. The vulnerability is the unsafe dependency acquisition and execution model, which makes future compromise of the npm package, publisher account, or release process directly actionable.
Attack Path
- An attacker compromises the npm publisher account, package release process, or another component capable of changing the version referenced by the
latesttag. - The attacker publishes a malicious package version and assigns or causes the
latesttag to reference it. - A user follows either installation command from
README.md. npx -ydownloads the attacker-controlled version without an interactive confirmation.- The package binary executes with ...[truncated 906 chars]
- An attacker compromises the npm publisher account, package release process, or another component capable of changing the version referenced by the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version, for example:bash npx -y --package @harrylabs/llm-knowledge-bases@0.4.1 \ llm-knowledge-bases-mcp \ --vault-root /absolute/path/to/your/obsidian-vault - Verify that the pinned version is the runtime version intended for Skill release
1.2.2; update it only through an explicit review and release process. - Use a lockfile or package-manager integrity metadata where the installation workflow supports it.
- Publish and verify a cryptographic integrity digest or signed provenance for the expected package artifact.
- Avoid automatic
-yexecution in security-sensitive setup documentation, or clearly warn users that the command downloads and executes third-party code. - Document the expected npm registry, package publisher, exact version, and verification procedure.
- Run the MCP server with least privilege and restrict its filesystem access to the intended Vault where the host supports sandboxing.
- Replace
