T08 · Insecure Dependencies
- Location
SKILL.md:64- Finding
Mutable MCP Dependency Is Downloaded and Executed with API Token Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 64–68
Vulnerability Type: Insecure dependency execution and supply-chain exposure
Risk Level: HighVulnerable Code
json "command": "npx", "args": ["-y", "@mondaydotcomorg/monday-api-mcp@latest"], "env": { "MONDAY_API_TOKEN": "<your-api-token>" }Technical Analysis
The MCP configuration invokes
npxwith-yand the mutable@latestpackage tag. Each installation can therefore retrieve and execute a package version that did not exist when this Skill was reviewed. The automatic confirmation option also removes an opportunity for the operator to inspect the selected version.The downloaded process is explicitly given
MONDAY_API_TOKEN. Consequently, the trust placed in the package extends to a sensitive credential and all monday.com resources accessible through that token. Although the referenced package appears to be associated with monday.com, using an unpinned release still leaves the effective executable payload dependent on future registry and publisher state.This behavior is not required at its current privilege level. The declared integration can operate with a reviewed, exactly pinned MCP release or use the documented GraphQL fallback without dynamically executing the latest package.
Attack Path
- An attacker compromises the package publisher account, release pipeline, package registry, or a future package release.
- The attacker publishes malicious code under a version selected by the
@latesttag. - An operator or Agent starts the configured MCP server.
npx -ydownloads and executes the mutable release without interactive review.- The malicious process reads
MONDAY_API_TOKENfrom its environment. - It can send the token or accessible monday.com data to an attacker-controlled service, issue unauthorized API operations, or use any additional local privileges available to the subprocess.
...[truncated 743 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version, for example:json "args": ["-y", "@mondaydotcomorg/monday-api-mcp@X.Y.Z"] - Use a lockfile and registry integrity hashes so the installed artifact is reproducible and tampering is detectable.
- Update dependencies only through a controlled review process that examines release provenance, changes, and security advisories.
- Prefer a preinstalled and verified executable rather than downloading code at invocation time.
- Run the MCP process in a sandbox with restricted filesystem access, an allowlisted network policy, and no access to unrelated environment variables or credentials.
- Use a dedicated, least-privilege monday.com credential where supported. Limit its permissions and rotate it immediately if dependency compromise is suspected.
- Consider the documented direct GraphQL fallback when MCP-specific functionality is unnecessary, while continuing to protect the authorization header and restricting requests to the official monday.com endpoint.
- Avoid relying on
-yfor security-sensitive installations; require explicit administrative review for dependency changes.
- Replace
