T08 · Insecure Dependencies
- Location
SKILL.md:66- Finding
Unpinned npm Package Is Downloaded and Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 66
Vulnerability Type: Supply-chain exposure caused by unpinned remote package execution
Risk Level: HighVulnerable Code:
sh npx -y @careermax/agent-toolkit mcpTechnical Analysis
The documented setup command invokes
npxwithout specifying an exact package version, lockfile, or integrity hash. Consequently, command behavior depends on whichever release of@careermax/agent-toolkitthe npm registry resolves at execution time rather than on the code reviewed with this skill.The
-yoption automatically accepts installation prompts. If the package, publisher account, release pipeline, or package-resolution path is compromised, a malicious release can be downloaded and executed without an additional interactive approval step. npm package lifecycle hooks and the package entry point can execute arbitrary code under the privileges of the user running the command.The skill requires
CAREERMAX_API_KEYto be present in the environment. A malicious package executed by this command could therefore attempt to read that credential and any other data accessible to the process.Attack Path
- An attacker compromises the npm publisher account, release pipeline, package source, or another relevant supply-chain component for
@careermax/agent-toolkit. - The attacker publishes a malicious release that becomes the version selected by the unpinned package reference.
- A user follows the setup instructions and runs
npx -y @careermax/agent-toolkit mcp. npxretrieves the attacker-controlled release and executes its lifecycle scripts or command entry point.- The payload runs with the invoking user's privileges and may read environment variables, including
CAREERMAX_API_KEY, access user-readable files, contact remote systems, or alter local data.
Impact Assessment
Successful exploitation could provide arbitrary code execution wit ...[truncated 668 chars]
- An attacker compromises the npm publisher account, release pipeline, package source, or another relevant supply-chain component for
- Remediation
View remediation
Remediation Suggestions
-
Pin the toolkit to an exact, reviewed version rather than allowing npm to select the latest release:
sh npx -y @careermax/agent-toolkit@<reviewed-exact-version> mcp -
Do not assume the skill's own version is also a valid toolkit version. Select and document a package version that has been independently reviewed and tested.
-
Prefer installing through a lockfile-backed project using
npm ci, with the lockfile committed and reviewed, instead of performing an ad hoc remote installation on each invocation. -
Verify package provenance and integrity using npm registry integrity metadata, trusted publishing or provenance attestations, and an approved package source.
-
Remove
-ywhere interactive review is operationally appropriate so unexpected installation activity is not silently accepted. -
Run the MCP process in a restricted environment with only the required credential, minimal filesystem access, and controlled outbound network access.
-
Use a dedicated, least-privileged CareerMax API key and establish rotation and revocation procedures in case dependency compromise is suspected.
-
