T08 · Insecure Dependencies
- Location
.mcp.json:3- Finding
Unpinned MCP Packages Are Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
.mcp.json, lines 3–12
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
json "playwright": { "command": "npx", "args": ["-y", "@playwright/mcp@latest"] }, "brave-search": { "command": "npx", "args": ["-y", "@brave/brave-search-mcp-server@latest"], "env": { "BRAVE_API_KEY": "${BRAVE_API_KEY}" } }Technical Analysis
The MCP configuration invokes
npxwith-yand mutable@latestpackage specifications. As a result, MCP startup may download and execute package versions that were not present during this audit. There is no exact version pin, committed lockfile, or integrity hash in the reviewed project to ensure that the executed artifacts match reviewed releases.The
-yoption suppresses installation confirmation, further reducing the opportunity to inspect version changes before execution. This creates a supply-chain exposure: compromise of either package, its maintainer account, or the relevant registry distribution channel could cause attacker-controlled code to execute locally.The Brave Search MCP process is also explicitly provided
BRAVE_API_KEY. Code executing inside that dependency can read the credential from its environment.Attack Path
- An attacker compromises the package maintainer account, package registry entry, or release process for one of the configured MCP packages.
- The attacker publishes a malicious version under the package’s
latestdistribution tag. - The Agent environment starts the configured MCP server.
npx -yretrieves the currentlatestversion without interactive confirmation.- The malicious package executes with the operating-system privileges of the user running the Agent.
- In the Brave Search server’s case, the malicious process reads
BRAVE_API_KEYfrom its environment and may transmit it externally. - Subject to the runtime user’s permissions and network controls, the package ...[truncated 663 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace both
@latestspecifications with reviewed, exact package versions. - Install dependencies through a committed manifest and lockfile rather than downloading mutable versions at MCP startup.
- Enforce package integrity verification and use a trusted registry configuration.
- Review dependency updates before changing pinned versions, including package provenance, release history, and transitive dependency changes.
- Avoid
npx -yfor first-time or unreviewed installations. Require an explicit provisioning or approval step where practical. - Run each MCP server in a restricted environment with minimal filesystem permissions and constrained outbound network access.
- Use a narrowly scoped, rate-limited, and readily rotatable Brave API key.
- Provide credentials only to the specific process that requires them, and rotate the key immediately if dependency compromise is suspected.
- Consider prebuilding or vendoring verified MCP artifacts so production startup does not retrieve executable code dynamically.
- Replace both
