T08 · Insecure Dependencies
- Location
README.md:196- Finding
Unpinned npm Package Is Downloaded and Executed with Access to Credentials
- Content
View full analysis
Vulnerability Details
File Location:
README.md:196-203; also present atREADME.md:53,59,SKILL.md:335, andreferences/MCP.md:8-29
Vulnerability Type: Supply-chain exposure through unpinned package execution
Risk Level: MediumVulnerable Code
json { "mcpServers": { "hashnet": { "command": "npx", "args": ["@hol-org/hashnet-mcp@latest", "up", "--transport", "stdio"] } } }Related commands include:
bash npx @hol-org/hashnet-mcp up --transport sse --port 3333 npm install @hashgraphonline/standards-sdkThe MCP configuration in
references/MCP.md:20-33additionally supplies the broker credential to the downloaded process:json { "mcpServers": { "hashnet": { "command": "npx", "args": ["@hol-org/hashnet-mcp@latest", "up", "--transport", "stdio"], "env": { "REGISTRY_BROKER_API_KEY": "your-api-key" } } } }Technical Analysis
npxcan download and immediately execute an npm package. The package is either unversioned or explicitly uses@latest, so the code executed by a future user can differ from the code available when this Skill was audited.The MCP process is designed to receive
REGISTRY_BROKER_API_KEY. The documentation also identifiesHEDERA_PRIVATE_KEYas an optional MCP environment variable. Consequently, compromise of the package, its publisher account, or one of its transitive dependencies could expose broker credentials or wallet material and execute arbitrary code with the user's operating-system privileges.The local
pnpm-lock.yamlpins@hashgraphonline/standards-sdk, but it does not constrain the separatenpx @hol-org/hashnet-mcp@latestcommand.Attack Path
- An attacker compromises the npm package, publisher account, or a dependency used by
@hol-org/hashnet-mcp. - A malicious release becomes the version resolved by
@latestor by ...[truncated 920 chars]
- An attacker compromises the npm package, publisher account, or a dependency used by
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestand unversioned package names with an exact, reviewed version. - Install the dependency through a committed manifest and integrity-protected lockfile rather than downloading it at MCP startup.
- Review and pin transitive dependencies as part of release maintenance.
- Run the MCP server under a dedicated, restricted operating-system account or sandbox.
- Pass only the environment variables required for the selected workflow.
- Do not expose
HEDERA_PRIVATE_KEYto discovery-only or chat-only MCP sessions. - Document package provenance, expected integrity, and a controlled upgrade process.
- Replace
