T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Unpinned Third-Party MCP Packages Are Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58-70
Vulnerability Type: Supply-chain risk from unpinned automatically executed dependencies
Risk Level: MediumVulnerable Code
json // .vscode/mcp.json { "mcpServers": { "filesystem": { "command": "npx", "args": ["-y", "@anthropic/mcp-filesystem"] }, "github": { "command": "npx", "args": ["-y", "@anthropic/mcp-github"], "env": { "GITHUB_TOKEN": "${env:GITHUB_TOKEN}" } } } }Technical Analysis
The documented MCP configuration invokes
npxwith the-yoption and package names that have no pinned versions. This causes npm packages to be retrieved and executed without interactive confirmation while allowing the resolved package contents to change after the Skill has been reviewed.The configuration does not specify exact audited versions, package integrity hashes, a lockfile, or other provenance controls. Consequently, compromise or replacement of a referenced package or one of its transitive dependencies could result in arbitrary code running with the privileges of the VS Code or Roo Code process.
The GitHub MCP server additionally receives
GITHUB_TOKENthrough its environment. Any code executed as that server can potentially read the token, making dependency compromise particularly significant.Attack Path
- An attacker compromises, replaces, or otherwise influences a referenced npm package or one of its transitive dependencies.
- A user copies the documented configuration into
.vscode/mcp.json. - Roo Code starts the configured MCP server by running
npx -ywith the unpinned package name. npxretrieves the package version currently resolved by the registry and executes it without confirmation.- Malicious package code executes under the user's account.
- For the GitHub server, the code reads
GITHUB_TOKENfrom its process environment and ...[truncated 814 chars]
- Remediation
View remediation
Remediation Suggestions
- Confirm and document the official, current package identifiers before recommending them.
- Pin every MCP package to an exact reviewed version rather than relying on registry resolution of an unversioned package name.
- Install dependencies through a committed lockfile and use a reproducible installation mechanism such as
npm ci. - Verify package provenance, publisher identity, signatures where available, and integrity hashes before execution.
- Avoid
npx -yfor security-sensitive integrations because it suppresses confirmation before download and execution. - Prefer a locally installed, reviewed executable referenced by a fixed path in the MCP configuration.
- Review and pin transitive dependencies as part of the dependency audit.
- Supply a dedicated, short-lived GitHub token with only the repository and operation scopes strictly required by the MCP server.
- Run MCP servers in a sandbox or container with restricted filesystem, environment-variable, and network access.
- Document package verification and update procedures so version changes require review before deployment.
