T08 · Insecure Dependencies
- Location
skill.json:25- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
skill.json:25-40andREADME.md:16-21
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
skill.json:25-40:json "mcp": { "command": "npx", "args": [ "-y", "@agentdocs1/mcp-server", "--http" ], "env": { "AGENTDOCS_URL": "${config.agentdocs_url}", "API_KEY": "${config.api_key}", "DEFAULT_PACKS": "data_analytics" }, "transport": "http", "url": "${config.agentdocs_url}/mcp" },The same unpinned invocation is presented to users in
README.md:16-21:json { "mcpServers": { "uplo-data-analytics": { "command": "npx", "args": ["-y", "@agentdocs1/mcp-server", "--http"],Technical Analysis
The configuration invokes
npxwith the-yoption and specifies@agentdocs1/mcp-serverwithout an exact version or package-integrity constraint. Consequently,npxmay retrieve and execute whichever package version the npm registry currently resolves for the package tag.This creates a mutable supply-chain execution path: the effective executable can change after this Skill has been reviewed, even when no files in the Skill itself change. The
-yoption suppresses the normal installation confirmation, making retrieval and execution unattended.Because the child process receives
API_KEYandAGENTDOCS_URLthrough its environment, a malicious future package release would execute in a context containing the user's UPLO credentials and endpoint information. The reviewed files do not establish that the current package is malicious; the vulnerability is the absence of dependency pinning and integrity controls.Attack Path
- An attacker compromises the npm package, its publisher account, or another part of its release pipeline.
- The attacker publishes a malicious version under
@agentdocs1/mcp-serverthat is selecte ...[truncated 1531 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a reviewed exact version rather than relying on the registry's current default tag:
json "args": [ "-y", "@agentdocs1/mcp-server@X.Y.Z", "--http" ] -
Prefer installing the dependency through a package manifest and committed lockfile rather than downloading it dynamically whenever the MCP server starts.
-
Verify package integrity using npm lockfile integrity metadata or an equivalent cryptographic verification mechanism.
-
Remove unattended installation behavior where practical. Avoid
npx -yfor dynamically resolved packages, or configurenpxso it can only use a previously installed and verified local dependency. -
Establish a controlled dependency-update process in which new versions are reviewed, tested, scanned, and explicitly approved before deployment.
-
Run the MCP process in a restricted environment with minimal filesystem access, constrained outbound networking, and no access to unrelated user credentials.
-
Apply least privilege to the UPLO API token. Limit it to the specific knowledge domains and operations required by this Skill, and avoid granting broad export or write permissions unless necessary.
-
Document the expected npm registry and package provenance to reduce dependency-confusion and registry-substitution risks.
-
