T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Global Installation of a Wallet-Enabled Third-Party Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18–20
Vulnerability Type: Unpinned and globally installed executable dependency
Risk Level: HighVulnerable Code
bash npm i -g @kaspacom/defi-mcpRelated wallet-enabled execution instructions at lines 27–29:
bash MCP_WALLET_KEY="0x..." MCP_NETWORK=igra node dist/mcp/index.jsTechnical Analysis
The Skill directs users to install the latest available version of
@kaspacom/defi-mcpglobally. It does not specify an exact version, integrity hash, lockfile, verified source repository, or package publisher validation procedure.npm packages may execute lifecycle scripts during installation. A global installation also exposes the installing user's environment to package-controlled code and makes the resulting executable available system-wide for that user. The project contains only
SKILL.md; therefore, the package implementation, installation scripts, transaction handling, and treatment ofMCP_WALLET_KEYcannot be independently verified from the audited artifact.The wallet-enabled invocation substantially increases the potential consequences. If the dependency or its publisher account is compromised, malicious package code could read the wallet key from the process environment, manipulate transaction parameters, or execute unrelated commands with the privileges of the user running npm or the MCP server.
Attack Path
- An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component for
@kaspacom/defi-mcp. - The attacker publishes a malicious version under the package's expected name.
- A user follows the Skill and runs the unpinned global installation command, which resolves to that malicious version.
- Malicious code executes through an npm lifecycle script or when the installed MCP server or CLI is launched.
- The user starts the service with `MCP_WALLET_KEY ...[truncated 1036 chars]
- An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component for
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an exact, reviewed version rather than resolving the latest release:
bash npm install --save-exact @kaspacom/defi-mcp@<audited-version> - Avoid global installation. Use a project-local dependency with a committed lockfile and execute it through a controlled project script.
- Publish or reference the verifiable source code corresponding to the pinned package release.
- Verify package provenance, publisher identity, signatures, and registry integrity metadata before installation.
- Review all npm lifecycle scripts. Where operationally feasible, install with lifecycle scripts disabled and explicitly run only audited build steps.
- Run the MCP server in a sandbox or container with minimal filesystem, network, and operating-system permissions.
- Do not expose a primary wallet private key directly through a general-purpose process environment. Prefer a hardware wallet, delegated signer, narrowly scoped signing service, or secret manager.
- Use a dedicated low-value wallet with only the funds and permissions required for the intended operation.
- Require an explicit transaction preview and user confirmation that displays the destination, asset, amount, slippage, network, and contract before signing.
- Test wallet-enabled operations on
igra-testnetorkasplex-testnetbefore mainnet use.
- Pin the dependency to an exact, reviewed version rather than resolving the latest release:
