T08 · Insecure Dependencies
- Location
SKILL.md:37- Finding
Unpinned Third-Party Package Installed and Registered as an MCP Server
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 37–44
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Mediumbash python3 -m pip install -U "clawlendar[all]" clawlendarOne-line registration in Claude Code:
bash python3 -m pip install -U "clawlendar[all]" && claude mcp add clawlendar -- clawlendarTechnical Analysis
The documented installation command uses
pip install -Uwithout an exact version constraint, integrity hashes, or a reviewed lockfile. It therefore installs the latest available release ofclawlendarand the dependencies included through itsallextra. The effective code can change after this skill has been audited.The second command immediately registers the externally installed
clawlendarexecutable as an MCP server. An MCP server can receive requests from the agent and execute with the permissions of the user who launched it. The submitted artifact contains onlySKILL.md; it does not contain the package implementation, dependency metadata, or executable source needed to verify filesystem, network, subprocess, and request-handling behavior.No malicious package behavior is demonstrated by the submitted file. The risk arises from the unpinned and unauditable supply-chain execution path.
Attack Path
- An attacker compromises a future
clawlendarrelease or one of the dependencies installed by theallextra. - A user follows the documented command, and
-Uresolves the compromised release because no exact version or hash is enforced. - Package installation or subsequent executable startup runs attacker-controlled code under the installing user's account.
- The command registers that executable as an MCP server.
- Future agent requests invoke or communicate with the compromised server, allowing its code to act within the operating-system permissions and accessible environment of that user.
Impact Assessment
Successful exploitation could execute arbitrar ...[truncated 556 chars]
- An attacker compromises a future
- Remediation
View remediation
Remediation Suggestions
- Replace the unconstrained upgrade with an exact, reviewed version, such as
clawlendar[all]==X.Y.Z. - Require package hashes through a locked requirements file and install with
pip --require-hashes. - Lock and audit all transitive dependencies, including dependencies introduced by the
allextra. - Avoid installing unnecessary optional dependencies; document and install only the extras required for the intended deployment.
- Include the corresponding implementation and dependency manifests in the reviewed artifact, or provide a reproducible source-to-package verification process.
- Separate installation from MCP registration so users can inspect and verify the installed executable before granting agent access.
- Run the MCP server in a restricted environment with minimal filesystem access, sanitized environment variables, constrained network access, and no elevated privileges.
- Document the server's required permissions and expected network, filesystem, and subprocess behavior.
- Replace the unconstrained upgrade with an exact, reviewed version, such as
