Skip to content

RP1 accepts unrelated version pins and misidentifies package/image names #672

Description

@Spectorian

Reproduction

Direct RP1 detector probes show three related operand-association problems:

Scanner input Observed behavior
npx evil-package Unpinned-package warning
npx evil-package --label helper@1.2.3 The unrelated argument suppresses that warning
npx evil-package@1.2.3 No unpinned-package warning, as expected for this check
Test component addition when npx is not found. Prose is interpreted as a package command
docker run --rm -e A my-image@sha256:abcdef --rm is treated as the image

These strings were scanned as data, not executed. The package name and abbreviated digest are synthetic; the digest example demonstrates operand extraction, not a valid or trusted image.

Expected behavior

The executable package's own version is what matters to the pin check. An unrelated argument or neighboring command must not satisfy it. Findings should name the actual package/image rather than a flag or prose fragment. Keep genuine mutable or ambiguous execution visible.

Related work

#639 and PR #646 cover npx word/line boundaries and YAML forms. The unrelated-argument pin bypass, same-line prose and Docker image cases remain outside that fix.

Relevant code

mcp_rug_pull.py:125.

Activity

  1. rng1995 commented on Oct 4, 2026

    @rng1995
    Collaborator

    Resolution verified: PR #683 has merged. RP1 now accepts a version pin only when attached to the relevant package/image operand rather than an unrelated argument. The MCP rug-pull regressions pass on current main. This issue was automatically closed by the merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions