What does IH-MCP-001 flag?
Reads MCP server configuration files and flags a server that is started from a downloaded script piped into a shell, or from an npx package that is not pinned to a version.
- A server command that pipes a downloaded script into a shell, for example a shell -c string that downloads and then runs. This is critical.
- npx with a package name that has no exact version, or with @latest.
- Not reported: a package pinned to an exact version, a local path, and a local node script.
Why it matters
An MCP server runs on your machine with your permissions and is started again every time the agent starts. If the start command pulls the newest version of a package, or pipes a script from the internet into a shell, whoever controls that package or URL controls the server tomorrow.
Severity: High by default. A download piped into a shell is raised to critical.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-MCP-001 fire on a safe skill?
- A package you trust and deliberately leave unpinned. The rule cannot tell a trusted publisher from a compromised one.
- Example configs in documentation folders that a scan walks.
How do I fix an IH-MCP-001 finding?
- Pin the package to an exact version, or to a commit.
- Run a reviewed local script instead of a remote one.
- Never pipe a downloaded script into a shell.
CLI guidance: Pin the package to an exact version or a commit, or run a local script. Do not pipe a downloaded script into a shell.
How do I tune or allow IH-MCP-001?
If you have reviewed an unpinned server and accept it, exclude that one config file with ignoreGlobs, or add a config suppression with a reason of at least 8 characters. Avoid turning the rule off for every MCP config.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-MCP-001.
What can IH-MCP-001 miss?
- Servers started from a wrapper script that itself downloads code at run time.
- What a pinned package does once it runs. Pinning fixes which code runs, not whether that code is safe.
- MCP configs in places the scan does not walk. It reads files in the folders you point it at.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.