T08 · Insecure Dependencies
- Location
SKILL.md:7- Finding
Unpinned Third-Party MCP Server Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:7
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: HighVulnerable Code Snippet:
yaml metadata: '{"openclaw": {"emoji": "\U0001F91D", "user-invocable": true, "requires": {"bins": ["npx"]}, "install": [{"name": "zetto-mcp", "type": "mcp", "command": "npx", "args": ["-y", "@zetto/mcp-server"]}]}}'Technical Analysis
The skill configures
npx -y @zetto/mcp-serveras its MCP server command. No exact package version or integrity value is specified. Consequently, package resolution depends on mutable npm registry state at execution time rather than on a dependency version that was reviewed with this skill.The
-yoption suppresses the normal installation confirmation, allowing the resolved package to be downloaded and executed automatically. The source code of@zetto/mcp-serveris not included in the audited project, so its implementation and effective behavior cannot be verified from this repository.This is particularly sensitive because the documented MCP capabilities include messaging, payments, escrow operations, knowledge-base management, and webhook configuration. A compromised or unexpectedly modified package release could operate inside the agent process with the permissions and credentials available to that process.
Attack Path
- An attacker compromises the npm account, publication pipeline, or distribution path for
@zetto/mcp-server, or causes an unsafe release to become the version selected by npm. - A user installs or invokes the Zetto skill.
- The skill executes
npx -y @zetto/mcp-server. npxresolves and downloads the mutable package release without asking the user for confirmation.- The downloaded package executes locally under the account running the agent.
- Malicious package code can access process-level resources available to it and may abuse configured credentials or exposed MCP ...[truncated 759 chars]
- An attacker compromises the npm account, publication pipeline, or distribution path for
- Remediation
View remediation
Remediation Suggestions
- Pin
@zetto/mcp-serverto a reviewed exact version, for example@zetto/mcp-server@1.2.3, rather than relying on npm's current resolution. - Remove automatic
-yexecution where practical so installation is an explicit, reviewable operation. - Commit lockfile and package-integrity metadata in the component responsible for installation.
- Verify package provenance using npm provenance attestations, trusted publishers, signatures, or an equivalent controlled artifact-verification process.
- Publish or vendor the relevant MCP server source so its implementation can be reviewed alongside the skill.
- Run the MCP server in a sandbox with minimal filesystem, network, environment-variable, and operating-system permissions.
- Provide sensitive credentials only when required and ensure payment, messaging, webhook, and destructive operations remain subject to explicit authorization checks outside the potentially mutable dependency.
- Establish dependency monitoring and a controlled update process that reviews each new package version before deployment.
- Pin
