T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned Third-Party Package Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 30-42
Vulnerability Type: Unpinned runtime dependency execution
Risk Level: MediumVulnerable Code
json If the tools are missing, configure the MCP server. Recommended remote configuration: { "mcpServers": { "mcp-diagram-generator": { "command": "npx", "args": ["-y", "mcp-diagram-generator"] } } }Technical Analysis
The recommended configuration invokes
npxwith the-yoption and an unversioned package name. This causes the package manager to resolve, download, and execute a package from the configured npm registry without interactive confirmation.No exact version, lockfile, integrity hash, or reviewed package source is included in the project. Consequently, the code executed at runtime may differ from the code that existed when this Skill was audited. The local
package.jsononly contains package metadata and does not constrain the MCP server dependency.This creates a supply-chain risk: compromise of the package publisher account, npm registry resolution, a transitive dependency, or a future package release could introduce arbitrary executable code.
Attack Path
- An attacker compromises the
mcp-diagram-generatorpackage, its publisher account, or a dependency resolved by the package. - The attacker publishes a malicious version that contains an installation hook or malicious MCP server implementation.
- An agent loads this Skill and determines that the required MCP tools are unavailable.
- Following
SKILL.md, the environment configures and runsnpx -y mcp-diagram-generator. npxretrieves the currently resolved package version and executes it without asking for confirmation.- The malicious code runs with the operating-system privileges and accessible environment of the agent process.
Impact Assessment
Successful exploitation could permit arbitrary code ...[truncated 499 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the MCP server to a specifically reviewed version, for example:
json { "command": "npx", "args": ["-y", "mcp-diagram-generator@1.2.1"] } - Prefer a locally installed dependency recorded in
package.jsonand a committed lockfile containing registry integrity metadata. - Review the pinned package, its lifecycle scripts, and its transitive dependencies before deployment.
- Avoid automatic installation at Skill runtime. Require explicit user or administrator approval before downloading executable packages.
- Where supported, install dependencies with lifecycle scripts disabled and only enable scripts that have been reviewed.
- Execute the MCP server in a restricted environment with minimal filesystem access, sanitized environment variables, and limited network permissions.
- Use trusted registry configuration and dependency-monitoring controls to detect publisher compromise, unexpected version changes, and integrity failures.
- Pin the MCP server to a specifically reviewed version, for example:
