T08 · Insecure Dependencies
- Location
README.md:133- Finding
Unpinned npm Runtime Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 133–146
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumThe documented setup commands execute the mutable
@latestversion of an external npm package:bash claude mcp add llm-wiki-karpathy -- \ npx -y --package @harrylabs/llm-wiki-karpathy@latest \ llm-wiki-karpathy-mcp \ --vault-root /absolute/path/to/your/obsidian-vaultbash npx -y --package @harrylabs/llm-wiki-karpathy@latest \ llm-wiki-karpathy-configs --vault-root /absolute/path/to/your/obsidian-vaultTechnical Analysis
The
@latesttag is mutable and does not identify a specific, reviewed package version. Each invocation can therefore download and execute different code without any corresponding change to this Skill. Thenpx -yoption suppresses the package installation confirmation, further reducing the opportunity for users to inspect unexpected dependency changes.The external npm runtime is not included in the audited project, so its implementation and future releases are outside this audit's verification boundary. If the package publisher account, npm package, release process, or an upstream dependency is compromised, malicious code could be distributed through the existing documented command.
Attack Path
- An attacker compromises the npm publisher account, release pipeline, package contents, or a relevant upstream dependency.
- The attacker publishes a malicious version under
@harrylabs/llm-wiki-karpathyand causes the mutablelatesttag to resolve to it. - A user follows either installation command in
README.md. npx -ydownloads the current package without requesting installation confirmation.- The package executable runs with the invoking user's operating-system privileges.
- The malicious process can access resources available to that user, including the vault path explic ...[truncated 574 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace
@latestwith an exact reviewed version, consistent with the documented runtime release:bash npx --package @harrylabs/llm-wiki-karpathy@0.4.4 \ llm-wiki-karpathy-mcp \ --vault-root /absolute/path/to/your/obsidian-vault -
Update the configuration-helper command in the same way.
-
Avoid
-ywhere interactive confirmation is practical, so unexpected installation behavior remains visible. -
Prefer a lockfile-backed installation workflow for repeatable dependency resolution.
-
Verify and publish the expected npm package integrity digest and provenance information.
-
Review new runtime versions before updating the pinned version, and use automated dependency and provenance checks in the release pipeline.
-
Run the MCP runtime with least privilege and restrict its filesystem access to the intended vault where the host environment supports sandboxing.
-
