T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party Packages Are Downloaded and Executed with Access to Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:5,SKILL.md:14-30, andSKILL.md:59-68
Vulnerability Type: Unpinned dependency execution and supply-chain exposure
Risk Level: MediumThe Skill instructs users to install or execute several third-party packages without pinning reviewed versions or verifying package integrity.
yaml metadata: {"clawdbot":{"emoji":"🔌","requires":{"bins":["mcps"]},"install":[{"id":"npm","kind":"node","package":"@maplezzk/mcps","bins":["mcps"],"label":"Install mcps"}]}}bash npm install -g @maplezzk/mcpsbash # Add fetch server (web scraping) mcps add fetch --command uvx --args mcp-server-fetch # Add PostgreSQL server mcps add postgres --command npx --args @modelcontextprotocol/server-postgres --env POSTGRES_CONNECTION_STRING="${DATABASE_URL}" # Add GitLab server mcps add gitlab --command npx --args gitlab-mcp-serverThe GitLab server configuration then provides a sensitive access token to one of these dynamically resolved executables:
json { "name": "gitlab", "type": "stdio", "command": "npx", "args": ["gitlab-mcp-server"], "env": { "GITLAB_PERSONAL_ACCESS_TOKEN": "${GITLAB_TOKEN}", "GITLAB_API_URL": "https://gitlab.com/api/v4" } }Technical Analysis
Commands such as
npm install,npx, anduvxcan retrieve and execute package code from external registries. No explicit versions, lockfiles, checksums, signatures, or other integrity controls are specified. Consequently, the code executed when a user follows these instructions may differ from the code available when the Skill was audited.This is particularly sensitive for
gitlab-mcp-server: the spawned process is intentionally givenGITLAB_PERSONAL_ACCESS_TOKEN. Any code running in that process can read the token from its environment. If the resolved package is compromised, replaced, or malicious, it can misuse or transmit the token ...[truncated 2201 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every package to a specific, reviewed version, including
@maplezzk/mcps,mcp-server-fetch,@modelcontextprotocol/server-postgres, andgitlab-mcp-server. - Use lockfiles and package-manager integrity metadata where supported. Verify package provenance, publisher identity, signatures, and checksums before execution.
- Avoid
npxoruvxbehavior that automatically retrieves an unspecified latest release. Preinstall verified artifacts or require execution with an exact version. - Prefer a project-local or isolated installation over
npm install -g. - Run each MCP server in a container, sandbox, or dedicated low-privilege account with restricted filesystem and outbound network access.
- Supply only narrowly scoped, short-lived credentials to each server. The GitLab token should be limited to the minimum projects and API permissions required.
- Keep database and GitLab credentials isolated so that a server receives only the credential necessary for its own function.
- Disable verbose logging in environments containing secrets and verify that the manager and child processes do not log environment-variable values.
- Document package verification and upgrade-review procedures so that dependency updates do not occur automatically without security review.
- Pin every package to a specific, reviewed version, including
