T08 · Insecure Dependencies
- Location
SKILL.md:32- Finding
Unpinned npm Package Execution with Access to Memos Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 32–39
Vulnerability Type: Unpinned third-party dependency executed throughnpx
Risk Level: MediumVulnerable Code:
json { "mcpServers": { "memos": { "command": "npx", "args": ["openclaw-memos-mcp"], "env": { "MEMOS_API_URL": "http://localhost:5230", "MEMOS_TOKEN": "<your-access-token>" } } } }Technical Analysis
The documented configuration directs
npxto executeopenclaw-memos-mcpwithout specifying an exact version. As a result, the package version resolved by npm may change between installations or executions. The project provides no lockfile, integrity hash, reviewed source revision, or registry restriction to ensure that the executed package is the version that was originally audited.The package process is also given
MEMOS_TOKENthrough its environment. Therefore, a compromised, malicious, or unexpectedly modified package release would receive the user's Memos credential while executing with the operating-system permissions of the MCP client.The package implementation is not included in the audited project, so its internal behavior cannot be verified from the available artifact. This finding concerns the unsafe dependency resolution and execution pattern documented by the skill; it does not establish that the named package is currently malicious.
Attack Path
- An attacker compromises the package publisher account, npm package, release process, or another relevant supply-chain component.
- The attacker publishes a malicious version under the same package name.
- A user follows the documented configuration and starts or restarts the MCP client.
npxresolves and executes the unpinned package version.- The malicious package inherits
MEMOS_API_URLandMEMOS_TOKENfrom the configured environment. - It uses the token to access or ...[truncated 803 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
openclaw-memos-mcpto an exact, reviewed version rather than allowingnpxto resolve an unspecified release. - Install dependencies through a committed lockfile and use deterministic installation, such as
npm ci, where applicable. - Verify package integrity and provenance, including the official publisher, repository, release signatures or attestations, and registry source.
- Configure npm to use an explicitly trusted registry and prevent unintended dependency substitution.
- Review new package versions before upgrading instead of automatically consuming the latest release.
- Run the MCP server in a restricted container, sandbox, or dedicated low-privilege OS account with minimal filesystem and network access.
- Issue a least-privilege Memos token limited to only the operations needed by the skill.
- Store the token through the MCP client's supported secret-management facility rather than in a broadly accessible configuration file.
- Rotate the token after suspected dependency compromise and monitor the Memos instance for unauthorized CRUD operations.
- Pin
