T08 · Insecure Dependencies
- Location
SKILL.md:113- Finding
Unpinned Remote Git Dependency Used as an Executable MCP Server
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 113–130
Vulnerability Type: Supply-chain exposure through an unpinned remote dependency
Risk Level: MediumVulnerable Code
json { "mcpServers": { "free-web-search": { "command": "free-web-search-mcp", "args": [] } } }bash pip install git+https://github.com/wd041216-bit/free-web-search-ultimate.gitTechnical Analysis
The documented installation command installs a Python package directly from a mutable GitHub repository without specifying an immutable commit, version tag, package hash, or signature verification. Package installation may execute attacker-controlled build logic. After installation, the resulting
free-web-search-mcpexecutable is registered as an MCP server and may be launched by the desktop client.Because the repository reference is unpinned, the code installed by users can differ from the code that was originally reviewed. Compromise of the upstream repository, maintainer account, or release process could therefore introduce arbitrary executable code into the installation path.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or another component of its publishing workflow.
- The attacker adds malicious package build logic or modifies the
free-web-search-mcpexecutable. - A user follows the documented unpinned
pip install git+https://...command. - Pip retrieves the current attacker-controlled repository contents and runs applicable package build or installation logic.
- The user adds the documented MCP configuration.
- Claude Desktop, Cursor, or another compatible client launches
free-web-search-mcp, executing the modified code under the user's account.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user who installs or launches the MCP server. Dep ...[truncated 407 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an audited immutable commit SHA or a specifically reviewed signed release rather than the repository's mutable default branch.
- Prefer a reproducible package artifact with cryptographic hashes, and enforce hash verification during installation.
- Verify release signatures or provenance attestations where available.
- Pin and audit transitive dependencies, including the listed Python requirements.
- Document the exact repository revision and dependency set covered by the security review.
- Install and run the MCP server in a dedicated virtual environment or sandbox with minimal filesystem, credential, and network access.
- Require users to review the resolved executable path and configuration before enabling the MCP server.
- Establish a controlled update process that reviews and verifies new revisions before deployment.
