T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Executable npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13–19
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumyaml install: - id: node kind: node package: mcporter bins: - mcporter label: Install mcporter (node)Technical Analysis
The installation metadata specifies the executable npm package
mcporterwithout an exact version or integrity constraint. Consequently, installation may resolve to a mutable future package release that was not represented by the audited project files.Although
SKILL.mdlinks to documentation formcporterversionv0.11.1, that documentation link does not constrain dependency resolution. The installed package could therefore differ from the reviewed version. Becausemcporteris executed as part of the skill and receives access to the configured Slack bearer token, compromise of its package, publisher account, or dependency chain could result in arbitrary code execution under the installer or agent runtime account.Attack Path
- An attacker compromises the
mcporternpm package, its publisher account, or a transitive dependency used by a newly published release. - The attacker publishes a malicious or backdoored package version.
- A user installs this skill after that release becomes the version selected by npm.
- The unpinned package declaration resolves to and installs the attacker-controlled release.
- Malicious lifecycle or runtime code executes with the privileges of the installation or agent process.
- The code may access
MAVERICK_SLACK_MCP_ACCESS_TOKEN, other environment variables, local data available to that process, and the network. - The stolen Slack token may be used within the permissions of its OAuth grant to access or alter Slack workspace data.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user or service acco ...[truncated 458 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
mcporterto an audited exact version rather than using an unconstrained package name, for examplemcporter@0.11.1if that version has been reviewed and is compatible. - Use a lockfile and verify package integrity hashes where the skill installation mechanism supports them.
- Install dependencies from the expected npm registry through an approved, integrity-enforcing package pipeline.
- Disable npm lifecycle scripts unless they are explicitly required and have been reviewed.
- Review both direct and transitive dependencies before upgrading the pinned version.
- Run the client with least privilege and expose only the environment variables required for operation.
- Restrict outbound network access to approved endpoints where practical.
- Rotate and revoke the Slack token promptly if dependency compromise is suspected.
- Pin
