T08 · Insecure Dependencies
- Location
references/mcp-setup.md:13- Finding
Unpinned Third-Party npm Package Is Automatically Downloaded and Executed with Dropbox Credentials
- Content
View full analysis
Vulnerability Details
File Location:
references/mcp-setup.md:13-18
Vulnerability Type: Insecure third-party dependency execution
Risk Level: Highjson "command": "npx", "args": ["-y", "dbx-mcp-server"], "env": { "DROPBOX_APP_KEY": "YOUR_APP_KEY", "DROPBOX_APP_SECRET": "YOUR_APP_SECRET", "DROPBOX_REFRESH_TOKEN": "YOUR_REFRESH_TOKEN" }Technical Analysis
The MCP configuration invokes
npx -y dbx-mcp-serverwithout specifying an exact package version or validating package integrity. When the MCP client starts the server,npxmay resolve, download, and execute the package version currently available from the configured npm registry. The-yoption suppresses the normal installation confirmation.This creates a supply-chain trust boundary that is not controlled by the reviewed artifact. A compromised package release, registry account, registry configuration, or transitive dependency could change the executed code after this skill has been reviewed.
The process is explicitly supplied with the Dropbox application key, application secret, and reusable refresh token. Therefore, any code executed through this dependency can read those values from its environment. The artifact contains no lockfile, integrity hash, vendored source, or implementation code through which the referenced package can be verified.
Attack Path
- A user copies the documented MCP configuration into an MCP-capable client.
- The client launches
npx -y dbx-mcp-server. npxresolves a mutable package version from the configured npm registry and automatically downloads it if necessary.- A compromised or unexpectedly modified package executes as the user running the MCP client.
- The package reads
DROPBOX_APP_KEY,DROPBOX_APP_SECRET, andDROPBOX_REFRESH_TOKENfrom its process environment. - It can use or disclose those credentials, access Dropbox within the granted scopes, manipulate files, or return deceptive MCP tool results.
Impa
...[truncated 563 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the legacy npm-based setup if the maintained Swift
dropbookexecutable is the intended implementation. - Otherwise, pin the package to an exact, reviewed version rather than allowing mutable resolution.
- Install dependencies separately under a committed lockfile and verify registry provenance and integrity before execution.
- Avoid
npx -yin persistent MCP configurations because it permits unattended package retrieval and execution. - Prefer a locally installed executable referenced by an absolute path after its source and release artifacts have been reviewed.
- Restrict Dropbox application scopes to the minimum required operations.
- Use isolated, revocable credentials and rotate the refresh token if an untrusted package may have received it.
- Run the MCP server in a restricted environment with limited filesystem and network access where practical.
- Remove the legacy npm-based setup if the maintained Swift
