T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Inconsistent and Unpinned npm Package Execution Enables Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-13 and 29-32
Vulnerability Type: Dependency confusion and execution of mutable third-party dependencies
Risk Level: HighVulnerable Code
yaml install: | npm install -g @scopeblind/red-team@latest protect-mcp@latestbash # Run the default attack suite against a policy npx scopeblind-red-team --policy protect-mcp.json # Run against a specific incident policy npx scopeblind-red-team --policy node_modules/protect-mcp/policies/clinejection.jsonTechnical Analysis
The installation instructions specify the scoped npm package
@scopeblind/red-team, but the execution examples invoke the distinct unscoped package namescopeblind-red-teamthroughnpx.If the requested unscoped package is not locally available,
npxmay retrieve and execute it from the npm registry. Consequently, users following the documented workflow can execute a package different from the scoped dependency they were instructed to install. This creates a package-confusion risk if the unscoped package is unintended, compromised, or controlled by another publisher.The installation also uses the mutable
latesttag for both dependencies. No exact version, lockfile, integrity hash, or vendored implementation is provided. The effective code can therefore change after this skill has been reviewed without any modification toSKILL.md. npm lifecycle scripts and package CLI entry points can execute arbitrary code with the permissions of the invoking user.The project contains no local implementation through which the claimed deterministic behavior, signed receipts, or badge generation can be independently verified.
Attack Path
- A user follows the skill instructions and globally installs
@scopeblind/red-team@latestandprotect-mcp@latest. - A malicious or compromised release is published under either mutable dependency tag, or an attacker controls or compromises the separately reference ...[truncated 1344 chars]
- A user follows the skill instructions and globally installs
- Remediation
View remediation
Remediation Suggestions
- Use the scoped package consistently in both installation and execution instructions. Confirm the executable name exported by the scoped package before documenting it.
- Pin every dependency to an exact, reviewed version instead of using
@latest. - Prefer project-local dependencies with a committed lockfile and npm integrity metadata rather than global installations.
- If the scoped package exports the
scopeblind-red-teambinary, invoke an explicitly pinned package, for example:
bash npx --package=@scopeblind/red-team@1.2.3 scopeblind-red-team --policy protect-mcp.json- When relying on an already installed and verified executable, use
npx --no-installor invoke the local binary directly so that execution fails instead of downloading an unexpected package. - Verify package publisher identity, provenance, signatures, registry source, lifecycle scripts, and release integrity before approving a version.
- Pin
protect-mcpto an audited version as well, and update it only through a controlled dependency-review process. - Run the benchmarking tool in a sandbox or isolated CI job with minimal filesystem access, no unnecessary credentials, restricted network access, and a non-privileged account.
