T08 · Insecure Dependencies
- Location
skill.json:25- Finding
Unpinned Third-Party Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
skill.json:25-30,README.md:21-27
Vulnerability Type: Unpinned dependency execution throughnpx
Risk Level: HighVulnerable Code
skill.json:25-30:json "mcp": { "command": "npx", "args": [ "-y", "@agentdocs1/mcp-server", "--http" ],README.md:21-27:json { "mcpServers": { "uplo-banking": { "command": "npx", "args": ["-y", "@agentdocs1/mcp-server", "--http"], "env": {Technical Analysis
The MCP configuration invokes
npx -ywith the package name@agentdocs1/mcp-serverbut does not specify an exact version or verify an integrity hash. If the package is not already available in the local cache,npxcan retrieve the current registry version and execute it immediately. The-yoption suppresses the normal installation confirmation.Consequently, the code that runs can change after this Skill has been reviewed. A malicious package release, compromised maintainer account, registry compromise, or other supply-chain incident could introduce arbitrary code without requiring any changes to the audited project.
Although this is primarily an insecure dependency issue, it also creates a dynamic remote code retrieval path. The selected classification reflects the project's reliance on an unpinned third-party package.
Attack Path
- An attacker compromises the package publisher, publication credentials, or upstream package distribution process.
- The attacker publishes a malicious version of
@agentdocs1/mcp-server. - A user installs or starts the Skill on a system where the malicious version is not already pinned locally.
npx -yretrieves the current package version without asking for confirmation.- The malicious package executes with the privileges of the user running the Agent.
- The package can read process environment variables, including the configur ...[truncated 927 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@agentdocs1/mcp-serverto a specific, reviewed version rather than resolving the latest available release. - Use a lockfile and verify package integrity with a trusted cryptographic hash.
- Remove
-yso that unexpected package retrieval is not silently accepted. - Prefer installing the dependency during a controlled deployment phase rather than downloading it when the Skill starts.
- Configure the package manager to use an approved registry and enforce package provenance or signature verification where supported.
- Run the MCP server in a sandbox or container with restricted filesystem and network access.
- Provide the process with a narrowly scoped, short-lived API token rather than a broadly privileged credential.
- Add dependency monitoring and require security review before upgrading the pinned version.
- Pin
