T08 · Insecure Dependencies
- Location
SKILL.md:288- Finding
Unreviewed npm Dependency Installation with Lifecycle Script Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:288-297
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: MediumComplete Code Snippet:
markdown ## Preflight Before running any operating mode, every MCP server under `mcp/<server>/` must have its `node_modules` installed. `node_modules/` is `.gitignored`, so a fresh clone (or any server added later) needs an install step: ```bash scripts/install_mcp_deps.sh # install for all mcp/*/ servers scripts/install_mcp_deps.sh swmm-calibration # install for one serverThe script loops over every
mcp/*/package.jsonand runsnpm install.text ### Technical Analysis The Skill makes dependency installation a mandatory preflight operation and states that `npm install` is run for every MCP server. By default, `npm install` can execute package lifecycle hooks such as `preinstall`, `install`, and `postinstall`. These hooks run as the user performing the installation and can execute arbitrary commands. The audited package does not contain `scripts/install_mcp_deps.sh`, the referenced `package.json` files, or corresponding lockfiles. Consequently, the audit could not verify dependency names, pinned versions, integrity metadata, registry sources, or lifecycle scripts. The use of `npm install`, rather than a reproducible locked installation such as `npm ci`, may also permit dependency resolution to change between executions. This creates a supply-chain trust boundary: the effective code executed during setup depends on external project content and packages that are not included in the reviewed artifact. ### Attack Path 1. An attacker compromises an npm dependency, publishes a malicious version within an accepted version range, or modifies an MCP server's package manifest or lockfile. 2. The user or Agent follows the mandatory preflight instruction and invokes `scripts/install_mcp_deps.sh`. 3. The instal ...[truncated 1071 chars]- Remediation
View remediation
Remediation Suggestions
- Include
scripts/install_mcp_deps.sh, all relevantpackage.jsonfiles, and lockfiles in the reviewable project artifact. - Commit a lockfile for every MCP server and replace
npm installwithnpm cito enforce reproducible dependency resolution. - Use
npm ci --ignore-scriptswhen lifecycle hooks are unnecessary. - If lifecycle hooks are required, explicitly inventory and review each permitted hook before installation.
- Pin dependency versions and verify package integrity, provenance, registry origin, and publisher identity.
- Run dependency installation in a restricted container or unprivileged environment without access to production credentials or sensitive user files.
- Avoid automatically installing dependencies for every MCP server. Install only the server required for the selected workflow.
- Add automated supply-chain checks, including lockfile validation, dependency auditing, and detection of unexpected lifecycle scripts.
- Include
