T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Execution of Unpinned Third-Party Packages and Source Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Credit Karma skill is coherent, but it should be reviewed carefully because it asks users to expose and store sensitive session cookies while running external code that can access financial data.
Install only if you are comfortable giving the MCP server and related extension access to your Credit Karma session and synced financial data. Prefer a pinned, audited package version, avoid storing full Cookie headers in project files, keep any .env or MCP config out of source control and backups, and remove stored cookies and the local SQLite database when no longer needed.
SKILL.md:17Execution of Unpinned Third-Party Packages and Source Code
SKILL.md:61Sensitive HttpOnly Cookies Exposed Through an External Browser Extension
SKILL.md:43Plaintext Storage of Full Credit Karma Session Cookies
Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.
Add to .mcp.json in your project or ~/.claude/mcp.json:
{
The skill instructs users to copy authentication cookies from DevTools or let an extension read HttpOnly cookies, but it does not prominently warn that these credentials may grant account access and that transaction data is persisted locally. For a financial-data skill, missing disclosure materially increases the risk of users exposing session secrets or storing regulated/sensitive data without informed consent.
The skill explicitly describes reading HttpOnly Credit Karma cookies via chrome.cookies.get and operating direct-to-API from Node, which matches credential-harvesting behavior even if framed as convenience. In the context of a personal-finance integration, browser-session cookie extraction can enable full account access and is especially dangerous because it targets highly sensitive financial data and bypasses safer delegated auth models like OAuth.
RKID=...; CKAT=eyJ...%3BeyJ...; ..." } } } }
Or use a `.env` file in the project directory with `CK_COOKIES=<value>`.
### Getting CK_COOKIES (optional)
Three onboarding paths, in priority order:
**1. fetchproxy extension (easiest — no env vars):** Install the [fetchproxy 0.3.0 extension](https://github.com/chrischall/fetchproxy), sign into creditkarma.com once, and leave `CK_COOKIES` **unset**. The MCP reads HttpOnly `CKAT` + `CKTRKID` cookies on the first tool call via `chrome.cookies.get`, then operates direct-to-API from Node.
**2. ck_set_session MCP tool:** From within Claude, call `ck_set_session` with a Cookie header you copied from DevTools (see below). The tool persists it to `.env`.
**3. Manual (DevTools):**
1. Log in to [creditkarma.com](https://www.creditkarma.com) in Chrome
2. DevTools → **Network** → any creditkarma.com request → **Request Headers**
3. Right-click the `cookie` header → **Copy value**
4. Paste into `CK_COOKIES` in your Claude
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
The MCP handles auth automatically once any of the three paths is configured.
- Access token: ~15 min TTL, auto-refreshed transparently
- Refresh token: ~8 hours TTL
- When expired:
- **fetchproxy path:** sign back into creditkarma.com — the MCP reads fresh cookies on the next tool call
The trigger description is broad enough to match generic personal-finance requests, which can cause the skill to activate when the user did not specifically intend to use Credit Karma. In this skill, unintended invocation is more concerning because the skill handles highly sensitive financial records and may prompt use of stored authentication state or local synced data.
No suspicious patterns detected.