T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned npm Packages Are Downloaded and Executed Through npx
- Content
View full analysis
" key=value --output json ``` Configuration invocation from `SKILL.md:25-28`: ```bash npx mcporter config add quotewise https://mcp.quotewise.io/mcp \ --header "User-Agent=quotewise-skill/1.0" --scope home ``` Guided setup command documented in `SKILL.md` and `README.md`: ```bash npx @quotewise/mcp setup ``` Equivalent unpinned `npx mcporter` and `npx @quotewise/mcp setup` commands are repeated throughout both documentation files. ### Technical Analysis `npx` can resolve, download, and immediately execute an npm package when an appropriate local package is not already installed. The commands do not specify reviewed package versions or verify package integrity. Consequently, the code executed by these instructions can change after the skill has been audited. This creates a software supply-chain exposure. A compromised maintainer account, malicious package release, registry compromise, or unexpected package resolution could cause users to retrieve and execute attacker-controlled package code. No evidence was found that the packages are currently malicious; the vulnerability is the unsafe, mutable dependency execution pattern. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, or its publication pipeline. 2. The attacker publishes a malicious version under `mcporter` or `@quotewise/mcp`. 3. A user follows the documented command without specifying a reviewed version. 4. `npx` resolves and downloads the malicious release. 5. Package lifecycle behavior or CLI entry-point code ...[truncated 925 chars]- Remediation
View remediation
call ... npx --yes @quotewise/mcp@ setup ``` 2. Replace placeholders with maintained version numbers and update them only after reviewing the corresponding package release. 3. Prefer installation through a project manifest and lockfile rather than repeated ad hoc downloads. 4. Verify package provenance, signatures, and registry integrity metadata where supported. 5. Disable or tightly control lifecycle scripts when they are unnecessary. 6. In higher-risk environments, execute third-party setup tools inside a sandbox or container with minimal filesystem, credential, and network access. 7. Document the expected package publisher, registry, version, and integrity digest so users can detect unexpected package resolution. ]]>
