T08 · Insecure Dependencies
- Location
references/INSTALL.md:5- Finding
Unpinned External MCP Implementation Executed by the Host
- Content
View full analysis
Vulnerability Details
File Location:
references/INSTALL.md:5-15,references/OPENCLAW_MCP_CONFIG.json:4-6, andreferences/OPENHANDS_MCP_CONFIG.json:4-6
Vulnerability Type: Unverified external executable dependency
Risk Level: MediumComplete Code Snippets
references/INSTALL.md:5-15:markdown 1. a local checkout of `agent-exporter` 2. `python3` 3. either: - `target/release/agent-exporter` - `target/debug/agent-exporter` - or a working `cargo` toolchain The bridge script is: ```text /absolute/path/to/agent-exporter/scripts/agent_exporter_mcp.pytext `references/OPENCLAW_MCP_CONFIG.json:4-6`: ```json "command": "python3", "args": [ "/absolute/path/to/agent-exporter/scripts/agent_exporter_mcp.py" ]references/OPENHANDS_MCP_CONFIG.json:4-6:json "command": "python3", "args": [ "/absolute/path/to/agent-exporter/scripts/agent_exporter_mcp.py" ]Technical Analysis
The package directs an AI host to execute
scripts/agent_exporter_mcp.pyfrom a separately obtained repository checkout. The installation instructions do not identify a canonical clone URL, require an immutable commit or release, or prescribe checksum or signature verification.The referenced Python implementation is not included in the audited artifact. Therefore, this package cannot establish what code will receive MCP requests, which subprocesses it may launch, or whether its access to local workspaces and transcript artifacts is restricted as documented.
This creates a supply-chain trust boundary: the security of the configured MCP server depends entirely on the provenance and integrity of an external checkout. An attacker who controls or modifies that checkout can replace the expected bridge with arbitrary Python code while retaining the legitimate-looking path and MCP server name.
Attack Path
- An attacker distributes a modified
agent-exportercheckout, compromises its source location, or alters an existing local checko ...[truncated 1286 chars]
- An attacker distributes a modified
- Remediation
View remediation
Remediation Suggestions
- Identify the authoritative source: Provide the exact official repository URL rather than referring only to “a local checkout.”
- Pin an immutable revision: Require a specific audited commit hash or immutable signed release instead of a mutable branch or unspecified checkout.
- Verify integrity: Publish and verify a SHA-256 digest or cryptographic signature for
agent_exporter_mcp.pyand any binary it invokes. - Bundle reviewed code where practical: Include the MCP bridge implementation in the reviewed package, or distribute it as a separately versioned and signed artifact.
- Validate before registration: Document commands or host-side checks that reject the bridge when its digest does not match the expected value.
- Apply least privilege: Run the MCP server in a sandbox with access limited to explicitly selected workspace directories. Deny unrelated filesystem, credential, subprocess, and network access unless required.
- Protect the checkout: Ensure the checkout and bridge script are owned by a trusted account and are not writable by untrusted users.
- Review transitive execution: Pin and verify the
agent-exporterbinary or Cargo dependencies that the bridge may invoke, not only the Python entry point.
