T08 · Insecure Dependencies
- Location
scripts/mcp_call.sh:77- Finding
Environment-Selected npm Package Can Be Downloaded and Executed at Runtime
- Content
View full analysis
` - wrapper then uses `npx -y ` - Recommended hardening for frequent use: - install once globally: `npm install -g @nitansde/mcp@latest` ``` Related instruction from `SKILL.md:85-86`: ```markdown - These commands assume `nitan-mcp` is already installed and available to `npx --no-install`. - If the user explicitly opts into install-on-demand mode, substitute a pinned package form such as `npx -y @nitansde/mcp@ ...`. ``` ### Technical Analysis The package passed to `npx` is obtained directly from the `NITAN_MCP_PACKAGE` environment variable. When `NITAN_MCP_ALLOW_INSTALL=1`, the wrapper invokes `npx -y` with that value without enforcing an allowlist, validating the package name, or requiring an exact immutable version. Using a Python argument array prevents shell metacharacter injection, but it does not prevent execution of a malicious or compromised npm package. `npx -y` may retrieve the selected package and execute its code, including applicable package lifecycle behavior, with the permissions and environment of the Skill process. The document ...[truncated 2145 chars]- Remediation
View remediation
` for installation. Reject paths, URLs, Git references, ranges, tags such as `latest`, and unrelated package names. 3. Remove the recommendation to install `@latest`. Document a reviewed exact version, such as: ```bash npm install -g @nitansde/mcp@1.2.3 ``` 4. Prefer eliminating runtime package installation entirely. Require administrators or users to install and verify the dependency separately, then retain only the `npx --no-install nitan-mcp` path. 5. Where runtime retrieval is unavoidable, verify package provenance and integrity before execution. Pin an exact version and validate expected registry metadata or integrity hashes. 6. Launch the MCP process with a minimized environment. Pass only variables required by the server rather than inheriting the complete Agent environment. 7. Run the external MCP package in a sandbox or restricted account with minimal filesystem and network permissions, especially when authentication variables are present. 8. Fail closed when `NITAN_MCP_ALLOW_INSTALL` contains any value other than the documented default, and emit a clear warning before initiating network retrieval or package execution. ]]>
