T08 · Insecure Dependencies
- Location
INSTALL.md:7- Finding
Unverified Third-Party npm Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:40-70andINSTALL.md:7-21
Vulnerability Type: Third-party supply-chain exposure through npm installation and automatic execution
Risk Level: MediumThe documentation directs users to retrieve and execute the external npm package
@vibo-dev/vibo-mcp@0.2.5. The implementation of that package is not included in the audited project, so its lifecycle scripts, transitive dependencies, network behavior, local file access, and handling ofVIBO_API_KEYcannot be independently verified from the available files.Complete relevant installation instructions from
INSTALL.md:bash # 1) verify the exact release before installing npm view @vibo-dev/vibo-mcp@0.2.5 version dist.integrity # 2) controlled global install (done once, not re-resolved on every start) npm install -g @vibo-dev/vibo-mcp@0.2.5 # 3) confirm vibo-mcp --versionThe alternative execution path is:
bash npx -y @vibo-dev/vibo-mcp@0.2.5The corresponding instructions in
SKILL.mdinclude:bash # 1) verify the version you are about to install npm view @vibo-dev/vibo-mcp@0.2.5 version dist.integrity # 2) controlled global install (lifecycle scripts run once, under your user) npm install -g @vibo-dev/vibo-mcp@0.2.5 # 3) confirm the installed version vibo-mcp --versionbash npm ls -g @vibo-dev/vibo-mcpTechnical Analysis
Version pinning reduces unintended upgrade drift but does not establish that the pinned artifact is trustworthy. The command
npm view ... dist.integrityonly displays registry-provided integrity metadata; the documented process does not compare the package against a digest obtained through an independent, trusted channel. Similarly,npm lsreports the installed dependency tree but does not independently verify the provenance or security of the installed code.A global npm installation can execute package lifecycle scrip ...[truncated 2179 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the reviewed MCP implementation and dependency lockfile in the project, or link each distributed release to publicly auditable source code and a reproducible build process.
- Publish a trusted SHA-512 digest for the exact package tarball through a channel independent of the npm registry, and document an explicit download-and-compare verification procedure.
- Avoid presenting
npm view ... dist.integrityornpm lsas independent integrity verification because both rely on npm metadata or installed package state. - Prefer downloading and verifying the package once, then running a locally controlled binary rather than using
npx -y. - Disable lifecycle scripts during installation with
--ignore-scriptsunless the package documents why they are required and those scripts have been reviewed. - Install the package in a dedicated, non-privileged environment rather than globally. Never run the installation as root or administrator.
- Execute the MCP server in a sandbox with filesystem access restricted to its designated storage directory and network access restricted to the documented license endpoint.
- Audit and lock all transitive dependencies, generate a software bill of materials, and scan releases for known vulnerabilities before promotion.
- Reconcile the Skill metadata version
0.2.6with the instructed package version0.2.5so users can clearly determine which implementation was reviewed. - Document key rotation and incident-response procedures in case
VIBO_API_KEYis exposed through a compromised package.
