T08 · Insecure Dependencies
- Location
skill.json:27- Finding
Automatic Execution of an Unpinned Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
skill.json:27-31
Additional Location:README.md:21-22
Vulnerability Type: Unpinned third-party dependency executed automatically throughnpx -y
Risk Level: HighVulnerable Code
skill.json:27-31:json "command": "npx", "args": [ "-y", "@agentdocs1/mcp-server", "--http" ],The documented installation configuration contains the same behavior at
README.md:21-22:json "command": "npx", "args": ["-y", "@agentdocs1/mcp-server", "--http"],Technical Analysis
The Skill starts the third-party npm package
@agentdocs1/mcp-serverthroughnpxwithout specifying an exact version or verifying an integrity hash. The-yoption suppresses the package installation confirmation. Consequently, startup may download and execute whichever package version the npm registry resolves at that time.This creates a supply-chain trust boundary in which the effective executable code can change after the Skill has been reviewed. If the package publisher account, package repository, release process, or registry distribution channel is compromised, a malicious release could execute locally without requiring further approval.
The MCP process receives the configured
API_KEYthrough its environment and communicates with the configured UPLO endpoint. Code running inside the dependency can therefore potentially read that credential and use the operating-system and network permissions inherited from the agent process.No evidence was found that the currently referenced package is malicious. The vulnerability is the unsafe, mutable, and confirmation-free dependency execution mechanism.
Attack Path
- An attacker compromises the npm publisher account, package build pipeline, source repository, or another part of the distribution chain for
@agentdocs1/mcp-server. - The attacker publishes a malicious package version under the legitim ...[truncated 1662 chars]
- An attacker compromises the npm publisher account, package build pipeline, source repository, or another part of the distribution chain for
- Remediation
View remediation
Remediation Suggestions
-
Pin the package to an audited exact version, for example:
json "args": [ "-y", "@agentdocs1/mcp-server@1.2.3", "--http" ]Replace the example version with a release that has been independently reviewed.
-
Prefer installing dependencies through a committed lockfile rather than resolving them dynamically whenever the Skill starts.
-
Verify package integrity using npm lockfile integrity metadata, trusted checksums, signed provenance, or an internally approved package mirror.
-
Remove automatic
-yinstallation where operationally possible. Installation and security review should occur as an explicit deployment step rather than during normal Skill execution. -
Run the MCP server in a restricted environment with:
- A dedicated, unprivileged operating-system identity.
- Read-only or narrowly scoped filesystem access.
- An outbound network allowlist limited to the required UPLO endpoint and package infrastructure used during controlled installation.
- No access to unrelated user credentials or agent secrets.
-
Issue an API token dedicated to this Skill and restrict it to the minimum required financial datasets, actions, tenant, and classification tiers.
-
Ensure the MCP package receives only required environment variables. Avoid exposing unrelated secrets to the child process.
-
Monitor dependency ownership, release provenance, vulnerability advisories, and unexpected package updates. Re-review the dependency before changing the pinned version.
-
Update the
README.mdexample to use the same pinned and verified deployment method so users do not reproduce the unsafe configuration.
-
