T08 · Insecure Dependencies
- Location
SKILL.md:68- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 68
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
bash npx mcporter config add firstdata https://firstdata.deepminer.com.cn/mcp --header 'Authorization=Bearer ${FIRSTDATA_API_KEY}'The same command is also documented in
references/firstdata-register.md, line 106.Technical Analysis
The documented command invokes
mcporterthroughnpxwithout specifying an exact package version, lockfile, or integrity hash. If the package is not already available in a trusted local installation,npxmay retrieve and execute the package version currently selected by the npm registry.Consequently, the executable code run by users can change after this Skill has been reviewed. A compromised package release, maintainer account, npm dependency, or registry resolution path could introduce arbitrary code without requiring changes to this repository.
The command also references
FIRSTDATA_API_KEY. A malicious package executing in the user's environment may be able to read that environment variable and other credentials accessible to the current process.Attack Path
- An attacker compromises the
mcporterpackage, one of its runtime dependencies, or an authorized publisher account. - The attacker publishes a malicious version that is selected when an unversioned
npx mcportercommand is resolved. - A user follows the Skill documentation and runs the command.
npxdownloads and executes the malicious package with the user's local operating-system privileges.- The package can access files, environment variables, network resources, and configuration writable by that user.
- The malicious process may steal
FIRSTDATA_API_KEY, modify MCP configuration, install additional payloads, or perform other actions allowed by the user's account.
Impact Assessment
Successful exploitation provides arbitrary code execution with the p ...[truncated 632 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
mcporterto an exact version that has been reviewed, rather than resolving the current registry version:
bash npx --yes mcporter@<audited-exact-version> config add firstdata https://firstdata.deepminer.com.cn/mcp --header 'Authorization=Bearer ${FIRSTDATA_API_KEY}'- Validate the selected package version and its dependency tree before recommending it.
- Use a lockfile and registry integrity metadata in a controlled installation workflow.
- Prefer executing a preinstalled, trusted CLI rather than allowing
npxto download code at invocation time. - Make the documented manual JSON configuration the primary setup method because it does not require executing a remotely resolved npm package.
- Run setup with least privilege and ensure the invoking environment exposes only the required secret.
- Add guidance for rotating the long-lived bearer token if package or workstation compromise is suspected.
- Pin
