T08 · Insecure Dependencies
- Location
mcporter.json:4- Finding
Unpinned ceaser-mcp Package Is Downloaded and Executed at Runtime
- Content
View full analysis
[args] ``` Examples include: ```bash npx -y ceaser-mcp shield USER_AMOUNT npx -y ceaser-mcp import "$UPDATED_BACKUP" npx -y ceaser-mcp notes npx -y ceaser-mcp unshield NOTE_ID RECIPIENT_ADDRESS ``` ### Technical Analysis The Skill invokes `ceaser-mcp` through `npx -y` without specifying an exact version. The package is not declared in `package.json` and is not covered by the integrity records in `package-lock.json`. Consequently, the code executed during a future Skill invocation can differ from the code that existed when this project was audited. This is especially sensitive because `ceaser-mcp` is trusted to: - Generate unsigned financial transactions. - Create and process private zero-knowledge note material. - Write `~/.ceaser-mcp/pending-tx.json`. - Read and modify the shared note database. - Submit unshield requests to the facilitator. - Produce transaction data later signed by the funded hot wallet. The repository's local `ethers` dependencies are integrity-locked, but this does not protect the dynamically downloaded `ceaser-mcp` executable. ### Attack Path 1. An attacker compromises the `ceaser-mcp` npm package, its publisher account, or a subsequently resolved package version. 2. The Agent runs `npx -y ceaser-mcp shield`, `import`, `notes`, or `unshield`. 3. `npx` retrieves and executes the attacker-controlled version without requiring interactive approval. 4. The malicious package runs with the Agent process's filesystem and network privileges. 5. It can alter the pending transaction, inspect private ZK note material, corrupt note state ...[truncated 722 chars]- Remediation
View remediation
