Reproduction
Direct RP1 detector probes show three related operand-association problems:
| Scanner input |
Observed behavior |
npx evil-package |
Unpinned-package warning |
npx evil-package --label helper@1.2.3 |
The unrelated argument suppresses that warning |
npx evil-package@1.2.3 |
No unpinned-package warning, as expected for this check |
Test component addition when npx is not found. |
Prose is interpreted as a package command |
docker run --rm -e A my-image@sha256:abcdef |
--rm is treated as the image |
These strings were scanned as data, not executed. The package name and abbreviated digest are synthetic; the digest example demonstrates operand extraction, not a valid or trusted image.
Expected behavior
The executable package's own version is what matters to the pin check. An unrelated argument or neighboring command must not satisfy it. Findings should name the actual package/image rather than a flag or prose fragment. Keep genuine mutable or ambiguous execution visible.
Related work
#639 and PR #646 cover npx word/line boundaries and YAML forms. The unrelated-argument pin bypass, same-line prose and Docker image cases remain outside that fix.
Relevant code
mcp_rug_pull.py:125.
Reproduction
Direct RP1 detector probes show three related operand-association problems:
npx evil-packagenpx evil-package --label helper@1.2.3npx evil-package@1.2.3Test component addition when npx is not found.docker run --rm -e A my-image@sha256:abcdef--rmis treated as the imageThese strings were scanned as data, not executed. The package name and abbreviated digest are synthetic; the digest example demonstrates operand extraction, not a valid or trusted image.
Expected behavior
The executable package's own version is what matters to the pin check. An unrelated argument or neighboring command must not satisfy it. Findings should name the actual package/image rather than a flag or prose fragment. Keep genuine mutable or ambiguous execution visible.
Related work
#639 and PR #646 cover npx word/line boundaries and YAML forms. The unrelated-argument pin bypass, same-line prose and Docker image cases remain outside that fix.
Relevant code
mcp_rug_pull.py:125.