T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Unpinned Third-Party Package Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:22-23
Vulnerability Type: Unsafe supply-chain dependency execution
Risk Level: MediumVulnerable Code
json "command": "npx", "args": ["-y", "@vbotholemu/mcp-domain-intel"],Technical Analysis
The documented MCP configuration invokes
npxwith the-yoption and a package name that has no exact version or integrity constraint. Consequently, following these instructions may cause npm to resolve, download, and execute whichever package release is current at execution time.The effective executable can therefore change after this source artifact has been reviewed. The
-yoption further removes the interactive confirmation that might otherwise alert the user to package installation. This creates a supply-chain boundary in which the security of local execution depends on the npm publisher account, registry resolution, and all content included in the subsequently resolved release.This finding does not establish that the current package is malicious. The risk arises because the instructions permit future, unaudited package content to be downloaded and executed automatically.
Attack Path
- An attacker compromises the npm publisher account, publishing workflow, or package distribution channel for
@vbotholemu/mcp-domain-intel. - The attacker publishes a malicious package release under the same package identity.
- A user copies the configuration from
SKILL.mdand starts the MCP server. npx -yresolves and downloads the unpinned package without an interactive installation prompt.- npm executes the package entry point.
- The malicious package runs with the operating-system permissions and environment available to the MCP host process.
Impact Assessment
Successful exploitation permits arbitrary code execution with the privileges of the user running the MCP client. Depending on the host environment, the malicious package could access readable files, environment v ...[truncated 369 chars]
- An attacker compromises the npm publisher account, publishing workflow, or package distribution channel for
- Remediation
View remediation
Remediation Suggestions
- Pin the package to a reviewed exact version, for example
@vbotholemu/mcp-domain-intel@1.0.0, rather than allowing registry resolution to select a later release. - Remove
-ywhere practical so unexpected installation requires explicit user confirmation. - Prefer installing dependencies through a committed lockfile and enforce package integrity verification during installation.
- Build and execute the reviewed local source artifact when reproducibility is required.
- Run the MCP server under a dedicated, least-privileged account or sandbox with narrowly scoped filesystem, environment-variable, and network access.
- Establish a release process using protected publisher credentials, multi-factor authentication, provenance attestations, and review of package contents before publication.
- Keep package identity and configuration consistent across
SKILL.md,README.md, andpackage.jsonso users do not unintentionally install a different package than the audited artifact.
- Pin the package to a reviewed exact version, for example
