Skip to content

RP1 npx pattern matches across line breaks, so a line ending in "npx" plus the next word becomes a command #639

Description

@JayOfTheKeyboard

_RP1_NPX_CMD (mcp_rug_pull.py:124-125) is npx\s+..., and \s matches newlines. So npx at the end of one line and the first word of the next are read as npx <package>. There is also no word boundary before npx.

Minimal repro: a skill whose frontmatter is

---
name: npx
description: repro
---

produces an RP1 finding for npx description (SARIF message: MCP server referenced without pinned version: 'npx\ndescription'). The same happens in wrapped prose, e.g. a line ending "...install it with npx" followed by a line starting "the ...".

Suggested fix: \bnpx[ \t]+(?:-+\w+[ \t]+)*..., keeping the match on one line. Happy to send a PR.

Activity

  1. agentsope commented on Sep 27, 2026

    @agentsope
    Contributor

    I opened #646 to address this. The RP1 npx matcher now requires a word boundary and uses spaces/tabs instead of \s, so it cannot combine text across line breaks. Added regressions for the frontmatter and wrapped-prose false positives, identifier suffixes, and normal npx -y commands. The focused MCP rug-pull tests pass (31); hosted test-unit and docker-smoke checks are still running.

  2. rng1995 commented on Oct 4, 2026

    @rng1995
    Collaborator

    PR-state snapshot checked on 2026-10-04:

    • PR #646 — open, non-draft; GitHub review decision: changes requested; latest reported check rollup: success.

    Keeping this issue open: the relevant implementation is not merged. Check/review status is a point-in-time snapshot, not a claim of merge readiness.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions