T08 · Insecure Dependencies
- Location
SKILL.md:138- Finding
Unpinned Third-Party Package Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 138
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code Snippet:
markdown - Local: `npx -y generect-ultimate-mcp@latest` with env `GENERECT_API_KEY`Technical Analysis
The documented local integration invokes
npxwith the mutable@latesttag and the automatic-confirmation option (-y). Following this instruction causes npm to download and execute whichever package release is identified as latest at execution time. The dependency is not pinned to an audited version, and the instruction provides no lockfile or package-integrity verification.Consequently, the code ultimately executed can change after the Skill has been reviewed. Although the audit found no evidence that the package is currently malicious, compromise of its publisher account, package ownership, release pipeline, or npm distribution path could turn this documented command into a supply-chain execution vector. The package also receives access to the
GENERECT_API_KEYenvironment variable as part of the documented setup.Attack Path
- An attacker compromises the npm publisher account, release pipeline, or another distribution component for
generect-ultimate-mcp. - The attacker publishes a malicious release that becomes the package's
latestversion. - A user or Agent follows the instruction in
SKILL.mdand runsnpx -y generect-ultimate-mcp@latest. npxdownloads and executes the attacker-controlled release without an interactive package confirmation.- The malicious process runs with the invoking user's privileges and can read environment variables available to it, including
GENERECT_API_KEY. - Subject to the invoking account's permissions and host controls, the process could exfiltrate credentials, access or alter local files, or perform network operations.
Impact Assessment
Successful exploitati ...[truncated 448 chars]
- An attacker compromises the npm publisher account, release pipeline, or another distribution component for
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version; for example, usegenerect-ultimate-mcp@X.Y.Z. - Record the approved dependency in a project manifest and lockfile rather than dynamically selecting a release at execution time.
- Require lockfile integrity verification, such as
npm ciwith a committedpackage-lock.json, in a controlled installation directory. - Verify and document the package's official publisher, source repository, release provenance, and expected integrity hash.
- Remove
-ywhere practical so unexpected downloads are not approved automatically. - Run the MCP package under a dedicated, least-privileged account or sandbox with narrowly restricted filesystem and network access.
- Expose
GENERECT_API_KEYonly to the process that requires it, use a minimally privileged and revocable key, and rotate it if dependency compromise is suspected. - Establish a review and update procedure so version changes occur only after code, provenance, and dependency-tree assessment.
- Replace
