T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party Package Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16-25
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: Highjson { "mcpServers": { "lovtrip": { "command": "npx", "args": ["-y", "lovtrip@latest", "mcp"], "env": { "AMAP_API_KEY": "your-amap-api-key" } } } }Technical Analysis
The configuration invokes
npxwith the mutable dependency specificationlovtrip@latest. The-yoption suppresses the normal installation confirmation, causing the currently published version of the package to be downloaded and executed automatically.Because
latestis a mutable registry tag, the code executed at runtime may differ from the version that existed when this skill was reviewed. The project does not provide an exact package version, a lockfile, an integrity hash, or local source code for the MCP implementation. Consequently, the effective executable payload cannot be fully established from the audited files.This creates a supply-chain trust boundary in which compromise of the package, its publisher account, or the package registry could cause arbitrary package lifecycle or runtime code to execute under the privileges of the user running the skill.
Attack Path
- An attacker compromises the
lovtrippackage publishing account, its release process, or the package distribution channel. - The attacker publishes a malicious release and assigns it to the
latestdistribution tag. - A user follows the documented configuration and starts the MCP server.
npx -y lovtrip@latest mcpresolves and downloads the attacker-controlled release without interactive confirmation.- Package lifecycle scripts or the package entry point execute locally with the privileges of the invoking user.
- The malicious package can access data and resources available to that process, including the configured `AMAP_AP ...[truncated 1020 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
lovtrip@latestwith an exact, reviewed version, such aslovtrip@1.2.3. Do not use mutable tags or permissive version ranges for executable dependencies. - Record and verify the package's cryptographic integrity using a lockfile or an equivalent checksum-verification mechanism.
- Document the expected registry, package publisher, source repository, and release-signing or provenance information so users can verify package authenticity.
- Prefer installing the reviewed dependency during a controlled setup phase rather than downloading code whenever the MCP server starts.
- Where practical, vendor the reviewed implementation or distribute a reproducible, signed artifact whose contents match the audited source.
- Disable package lifecycle scripts during installation unless they are explicitly required and independently reviewed.
- Run the MCP server in a restricted environment with minimal filesystem access, constrained outbound networking, and no unrelated credentials.
- Provide
AMAP_API_KEYas a narrowly scoped secret, rotate it periodically, and ensure it is not exposed to other child processes or logs. - Establish an update procedure that reviews new versions before changing the pinned dependency and its verified integrity metadata.
- Replace
