T08 · Insecure Dependencies
- Location
skill.json:25- Finding
Automatic Execution of an Unpinned Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
skill.json, lines 25–29
Vulnerability Type: Unpinned dependency downloaded and executed automatically
Risk Level: HighVulnerable Code:
json "command": "npx", "args": [ "-y", "@agentdocs1/mcp-server", "--http" ],Technical Analysis
The Skill launches
@agentdocs1/mcp-serverthroughnpxwithout specifying an exact package version or integrity digest. The-yoption automatically accepts installation prompts, allowing npm to download and execute the package version resolved at runtime.Consequently, the code executed during future installations can differ from the code that was available when the Skill was audited. The launched package also receives the configured
API_KEYandAGENTDOCS_URLenvironment variables. This creates a supply-chain trust boundary in which a compromised npm package, publishing account, or newly published malicious release could execute arbitrary code and access those credentials.The audit found no evidence that the current package is malicious. The vulnerability is the unsafe, mutable dependency execution mechanism.
Attack Path
- An attacker compromises the npm package, its maintainer account, or its publishing workflow.
- The attacker publishes a malicious release under
@agentdocs1/mcp-server. - A user installs or starts the Skill after that release becomes the version resolved by npm.
npx -ydownloads the package and executes it without an interactive approval step.- The malicious package reads
API_KEY,AGENTDOCS_URL, or other data available to the process. - The payload may exfiltrate credentials, access the configured UPLO service, or perform actions with the operating-system privileges of the Agent process.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the account running the Skill. The attacker could potentially:
- Read the U ...[truncated 509 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@agentdocs1/mcp-serverto a reviewed, exact version rather than resolving the latest available release. - Install the dependency through a committed lockfile and use a reproducible installation command such as
npm ci. - Verify package provenance, signatures, and integrity hashes before execution.
- Remove
-ywhere practical so unexpected installation or version changes require explicit approval. - Prefer a locally installed, reviewed executable over runtime package retrieval.
- Run the MCP server in a restricted container or sandbox with minimal filesystem and network access.
- Supply a narrowly scoped, revocable API token and rotate it after any suspected dependency compromise.
- Monitor package ownership, release history, and security advisories, and require dependency review before upgrades.
- Pin
