T08 · Insecure Dependencies
- Location
skill.json:30- Finding
Automatic Execution of an Unpinned Third-Party Package
- Content
View full analysis
Vulnerability Details
File Location:
skill.json:30-35
Vulnerability Type: Supply-chain risk through unpinned dependency execution
Risk Level: HighComplete Code Snippet:
json "mcp": { "command": "npx", "args": [ "-y", "@agentdocs1/mcp-server", "--http" ],The same insecure installation pattern is also documented in
README.md:21-24:json "command": "npx", "args": ["-y", "@agentdocs1/mcp-server", "--http"],Technical Analysis
The skill invokes
npxwith the-yoption to download and execute@agentdocs1/mcp-serverautomatically. The package reference does not specify an exact version or integrity hash. Consequently, the code executed when the skill starts can change after this skill package has been reviewed.The
-yoption suppresses the package-installation confirmation, eliminating an opportunity for the user to review the resolved package and version. If the publisher account, registry, package, or release process is compromised, a malicious release could be selected and executed without any corresponding modification to this repository.Attack Path
- An attacker compromises the package publisher, publication credentials, registry delivery path, or another relevant supply-chain component.
- The attacker publishes a malicious version under
@agentdocs1/mcp-server. - A user installs or starts this skill.
npx -yresolves the unpinned package reference and downloads the currently selected registry version.- The malicious package executes with the operating-system privileges and environment available to the agent process.
- The package can attempt to read accessible files and environment variables, including the configured UPLO API credential, and communicate with network destinations allowed by the host.
Impact Assessment
Successful exploitation could result in arbitrary code execution under the account running ...[truncated 584 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed, exact version, such as
@agentdocs1/mcp-server@X.Y.Z; do not use a range or floating tag. - Verify the package artifact with a trusted lockfile, registry integrity metadata, checksum, or signature.
- Remove automatic confirmation where practical and require explicit approval before installing a previously unavailable package.
- Prefer installing dependencies during a controlled build process rather than downloading executable code when the skill starts.
- Monitor the package version and provenance and require security review before upgrades.
- Run the MCP server in a sandbox or container with a read-only filesystem, minimal environment exposure, restricted outbound networking, and a dedicated low-privilege account.
- Provide a narrowly scoped, short-lived API token and rotate it if dependency compromise is suspected.
- Pin the dependency to a reviewed, exact version, such as
