T08 · Insecure Dependencies
- Location
SKILL.md:46- Finding
Unpinned Third-Party Package Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 46-48
Vulnerability Type: Unpinned npm dependency execution
Risk Level: Highbash npx x402-proxy setup # one-time: generate or import a wallet npx x402-proxy wallet info # show address + USDC balance npx x402-proxy mcp add glim https://glim.sh/mcp # register glim in your MCP client behind a paying proxyTechnical Analysis
The documented commands instruct users to retrieve and execute
x402-proxythroughnpxwithout specifying a version, integrity hash, lockfile, or signature verification mechanism. Consequently, the package version and effective code executed may change after the Skill has been reviewed.This dependency is used for security-sensitive operations: generating or importing a cryptocurrency wallet, displaying wallet information, authorizing automatic payments, proxying MCP traffic, and changing MCP client configuration. An attacker who compromises the npm package, its publisher account, or its distribution process could cause arbitrary code to execute with the privileges of the user following these instructions.
No evidence establishes that the current package is malicious. The vulnerability is the unsafe, unpinned supply-chain execution pattern and the sensitive authority granted to the downloaded package.
Attack Path
- An attacker compromises the
x402-proxynpm package, its publisher credentials, or a future release distributed under the same package name. - The attacker publishes a modified package version containing malicious lifecycle or runtime code.
- A user follows
SKILL.mdand invokes one of the unversionednpx x402-proxycommands. npxresolves and downloads the attacker-controlled release.- The downloaded package executes under the invoking user's account.
- The malicious code accesses wallet material or local configuration available to tha ...[truncated 837 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
x402-proxyto a specifically reviewed version rather than allowingnpxto resolve an unspecified current release. - Verify the selected release against an authenticated integrity value or trusted package signature before execution.
- Publish the expected package owner, source repository, version, and checksum so users can validate provenance.
- Prefer a locked, auditable installation workflow over implicit download-and-execute behavior.
- Review the package source and its dependency tree before recommending it for wallet operations.
- Use a dedicated wallet containing only the minimum funds required for expected calls.
- Avoid importing a high-value or general-purpose wallet into the proxy.
- Require explicit transaction limits and user confirmation where supported, rather than granting unrestricted automatic payment authority.
- Document where wallet keys are stored, which filesystem permissions protect them, and how users can revoke or rotate affected credentials.
- Back up MCP configuration before modification and verify the resulting endpoint and proxy settings after setup.
- Pin
