Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate Chrome DevTools MCP guide, but it gives an AI broad browser access while also recommending unpinned runtime installation and a token-reading example without adequate safety boundaries.

Install only if you are comfortable giving an AI-assisted MCP server control over Chrome. Use a dedicated disposable browser profile, avoid personal or production logged-in sessions, do not ask it to read tokens/cookies/auth headers, and pin the npm package to a reviewed version instead of using @latest.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Error
Location
guides/01-installation.md:16
Finding

Unpinned npm Package Is Downloaded and Executed Automatically

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
guides/02-quickstart.md:113
Finding

Documentation Encourages Extraction of Browser Authentication Tokens

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
troubleshooting.md:242
Finding

Troubleshooting Command Terminates All Matching Chrome Processes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The JavaScript execution section demonstrates accessing token material from localStorage without noting that such values are sensitive credentials. This is especially dangerous in a tool designed to let an AI execute code in a real browser, because it provides a straightforward recipe for harvesting bearer tokens from authenticated sessions.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · troubleshooting.md (reported line 109)May include surrounding context.

bash
# 清理 npx 缓存后重试
npx clear-npx-cache
npx -y chrome-devtools-mcp@latest --headless

# Windows 增加超时时间(在 .codex/config.toml 中)
# startup_timeout_ms = 20_000

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · troubleshooting.md (reported line 109)May include surrounding context.

bash
# 清理 npx 缓存后重试
npx clear-npx-cache
npx -y chrome-devtools-mcp@latest --headless

# Windows 增加超时时间(在 .codex/config.toml 中)
# startup_timeout_ms = 20_000

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · troubleshooting.md (reported line 212)May include surrounding context.

claude mcp add chrome-devtools --scope user npx chrome-devtools-mcp@latest

text

或手动添加 JSON 配置到 `~/.claude/settings.json`:
```json
{
  "mcpServers": {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill description and usage guidance are presented only in Chinese, with no indication that language choice is optional or that the skill is intentionally limited to a Chinese-speaking audience. This creates a locale/language policy issue because the file effectively imposes a specific language without offering user choice or documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises browser console inspection, network interception, response-body access, form interaction, screenshots, and arbitrary JavaScript execution, but does not warn users that these capabilities can expose credentials, session tokens, personal data, or sensitive internal application content. In this context, omission is security-relevant because the tool is specifically designed to inspect and automate a real browser, increasing the chance of accidental access to sensitive data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx chrome-devtools-mcp without a pinned version, which can pull the latest package at execution time. That creates a supply-chain risk: a malicious or compromised upstream release could be fetched and executed automatically in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The installation command uses an unpinned package reference (npx chrome-devtools-mcp@latest / effectively latest resolution), which allows future upstream package changes or a compromised publish to be pulled at install time. Because this MCP server is intended to control a real browser from an AI tool, a malicious update could gain broad access to browsing sessions, page content, cookies, screenshots, and local workflow context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The verification flow instructs users to let the AI open a live browser page and capture screenshots, but it does not clearly warn that browser control can expose page contents, authenticated sessions, console data, or sensitive information visible in tabs. In the context of an AI-integrated browser-control MCP, this omission increases the chance that users test the feature against non-public content without understanding the privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation advertises visibility into full request URLs, headers, and response bodies without any warning about sensitive data exposure. Network traces commonly contain API keys, bearer tokens, session identifiers, PII, and confidential business data, so encouraging unrestricted inspection increases the chance an agent exfiltrates or unnecessarily processes secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The browser automation example includes entering a username and password directly in the prompt, normalizing the practice of placing credentials into agent-visible instructions. In an AI/browser automation environment, this can cause credentials to be logged, retained in transcripts, or exposed to connected tools and debugging artifacts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide explicitly instructs the agent to execute JavaScript that reads window.localStorage.getItem('user_token'), which is a direct credential/token extraction pattern. In the context of an AI-controlled browser debugging skill, this extends beyond ordinary diagnostics into accessing secrets that could authenticate as the user against backend services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly recommends connecting the tool to an already running Chrome instance for debugging logged-in pages or a specific browser profile, but it does not warn that the MCP server can then access highly sensitive session context. In this skill’s context, that is materially risky because the exposed tools include navigation, JavaScript evaluation, network inspection, console access, screenshots, and typing/clicking, which together can read or manipulate authenticated content and profile data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and prohibits natural-language policy violations such as forcing a specific language without opt-in. This file presents all operational instructions in Chinese and does not offer an alternative language, language selection, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Using npx -y chrome-devtools-mcp@latest --headless executes the latest package version at runtime, which creates a supply-chain trust risk: a compromised upstream release or dependency could run arbitrary code on the user's machine. In the context of an MCP/browser-control tool, that code would run with the user's local privileges and could also access browser automation capabilities, making the impact more serious than a normal CLI utility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

claude mcp add chrome-devtools --scope user npx chrome-devtools-mcp@latest configures the agent to launch an unpinned package from the registry. That means future executions may silently pull changed code, enabling arbitrary code execution via a malicious or hijacked package release and persisting that risk in the agent configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes a destructive operational step (pkill -f "Google Chrome") that can abruptly close all Chrome windows and interrupt unsaved work. Under SQP-2 for markdown files, actions that may affect user data or system state should include a user warning, but no such warning is present here.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The manual test command npx -y chrome-devtools-mcp@latest --headless again relies on an unpinned latest package, exposing users to registry and dependency compromise at execution time. Because this tool controls Chrome DevTools, compromise could enable browser interaction, local data access through the browser context, or misuse of authenticated sessions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Natural-language policy requires flagging cases where a skill forces a specific language without user opt-in. This installation guide appears fully Chinese-language and does not indicate that other language options are available or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 适用于所有文件,包含自然语言中的语言/locale 政策问题。该文档标题及全文均固定为中文,未见提供用户语言选项、双语说明或对语言限制的合理化说明,可能与要求用户可选择语言/locale 的组织政策不一致。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.