T08 · Insecure Dependencies
- Location
SKILL.md:73- Finding
Unpinned Executable Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 73–77
Vulnerability Type: Unpinned executable dependency and automatic MCP configuration
Risk Level: MediumVulnerable Code
bash pip install neural-memory nmem initThe document states that this creates the default brain under
~/.neuralmemory/and automatically configures MCP.Technical Analysis
The Skill instructs users or agents to install the latest available release of the third-party
neural-memorypackage without specifying an exact version, cryptographic hashes, a lockfile, or a verified source. It then immediately executes the package-providednmem initcommand.Because the dependency's implementation is not included in the audited project, its behavior cannot be reviewed from this artifact. The package version resolved at installation time may also differ from the version intended by the Skill author. Executing
nmem initincreases the exposure because package-controlled code can create persistent local state and modify MCP configuration. Later memory operations may consequently invoke code from the unresolved package release.This is a supply-chain weakness rather than confirmation that the current external package is malicious.
Attack Path
- An attacker compromises the dependency publisher, distribution account, or package delivery channel.
- The attacker publishes a malicious or unexpectedly modified release under the referenced package name.
- A user or agent follows the Skill instruction and runs
pip install neural-memory. - The package manager resolves and installs the attacker-controlled release because no exact version or hash is required.
- The user or agent runs
nmem init, executing package-provided code. - The malicious package can alter MCP configuration or arrange for its code to run during subsequent memory operations.
Impact Assessment
Successful exploitation would execute dependency-controlled code with the operating-s ...[truncated 505 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
neural-memoryto a specifically reviewed version rather than installing the latest release. - Publish a lockfile or constraints file containing cryptographic hashes, and install with pip's
--require-hashesoption. - Document the trusted package index and source repository; reject unexpected indexes and dependency-confusion sources.
- Include or vendor the relevant implementation so reviewers can audit the code executed by the Skill.
- Verify package provenance and release signatures where supported.
- Separate installation from initialization and require explicit user confirmation before
nmem initmodifies MCP configuration. - Run initialization and the MCP service with least privilege in an isolated environment.
- Document all files and configuration entries created or changed by initialization and provide a safe removal procedure.
- Pin
