T08 · Insecure Dependencies
- Location
skill.json:21- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
skill.json:21-28; also documented inREADME.md:16-26
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: HighVulnerable Code
skill.json:21-28:json "mcp": { "command": "npx", "args": ["-y", "@agentdocs1/mcp-server", "--http"], "env": { "AGENTDOCS_URL": "${config.agentdocs_url}", "API_KEY": "${config.api_key}", "DEFAULT_PACKS": "legal" },README.md:16-26:json { "mcpServers": { "uplo-legal": { "command": "npx", "args": ["-y", "@agentdocs1/mcp-server", "--http"], "env": { "AGENTDOCS_URL": "https://your-instance.uplo.ai", "API_KEY": "your-api-key", "DEFAULT_PACKS": "legal" } }Technical Analysis
The configuration invokes
npxwith the-yoption and a package name that has no exact version or integrity constraint. Consequently, npm can retrieve and execute the package version currently resolved from the configured registry without interactive confirmation.This creates a supply-chain trust boundary outside the audited project. The effective executable can change after this skill has been reviewed. A compromised maintainer account, malicious package release, registry compromise, or unsafe registry substitution could cause attacker-controlled JavaScript to execute when the MCP server starts.
The spawned package receives
API_KEYandAGENTDOCS_URLthrough its environment. Therefore, dependency compromise could expose the UPLO credential and organization endpoint directly. The process also executes with the operating-system privileges and environmental access granted to the agent runtime.Attack Path
- An attacker compromises the
@agentdocs1/mcp-serverpublishing account, its build pipeline, or a registry used by the deployment. - The attacker publishes a malicious version under the same package ...[truncated 1447 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a reviewed, immutable version, for example:
json "args": ["-y", "@agentdocs1/mcp-server@1.2.3", "--http"] -
Prefer a controlled installation step using a committed lockfile and
npm cirather than downloading code dynamically whenever the skill starts. -
Verify package integrity with lockfile integrity hashes, provenance attestations, and trusted-registry enforcement.
-
Disable registry overrides and prevent fallback to untrusted package registries in the execution environment.
-
Review the package contents and transitive dependency tree before upgrading the pinned version.
-
Run the MCP server in a restricted container or sandbox with minimal filesystem permissions, limited outbound network access, and no unrelated environment variables.
-
Issue a narrowly scoped UPLO token that permits only the operations required by this skill. Avoid granting administrative, cross-tenant, or unrestricted export privileges.
-
Rotate the API token promptly if an untrusted dependency version may already have executed.
-
Monitor package-version changes, token use, unusual organization-context exports, and outbound network connections from the MCP process.
-
Update the installation example in
README.md:16-26so users are not instructed to deploy the unpinned command.
-
