T08 · Insecure Dependencies
- Location
guides/01-installation.md:16- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a legitimate Chrome DevTools MCP guide, but it gives an AI broad browser access while also recommending unpinned runtime installation and a token-reading example without adequate safety boundaries.
Install only if you are comfortable giving an AI-assisted MCP server control over Chrome. Use a dedicated disposable browser profile, avoid personal or production logged-in sessions, do not ask it to read tokens/cookies/auth headers, and pin the npm package to a reviewed version instead of using @latest.
guides/01-installation.md:16Unpinned npm Package Is Downloaded and Executed Automatically
guides/02-quickstart.md:113Documentation Encourages Extraction of Browser Authentication Tokens
troubleshooting.md:242Troubleshooting Command Terminates All Matching Chrome Processes
The JavaScript execution section demonstrates accessing token material from localStorage without noting that such values are sensitive credentials. This is especially dangerous in a tool designed to let an AI execute code in a real browser, because it provides a straightforward recipe for harvesting bearer tokens from authenticated sessions.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
# 清理 npx 缓存后重试
npx clear-npx-cache
npx -y chrome-devtools-mcp@latest --headless
# Windows 增加超时时间(在 .codex/config.toml 中)
# startup_timeout_ms = 20_000
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
# 清理 npx 缓存后重试
npx clear-npx-cache
npx -y chrome-devtools-mcp@latest --headless
# Windows 增加超时时间(在 .codex/config.toml 中)
# startup_timeout_ms = 20_000
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
claude mcp add chrome-devtools --scope user npx chrome-devtools-mcp@latest
或手动添加 JSON 配置到 `~/.claude/settings.json`:
```json
{
"mcpServers": {
The entire skill description and usage guidance are presented only in Chinese, with no indication that language choice is optional or that the skill is intentionally limited to a Chinese-speaking audience. This creates a locale/language policy issue because the file effectively imposes a specific language without offering user choice or documenting a justified regional scope.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill advertises browser console inspection, network interception, response-body access, form interaction, screenshots, and arbitrary JavaScript execution, but does not warn users that these capabilities can expose credentials, session tokens, personal data, or sensitive internal application content. In this context, omission is security-relevant because the tool is specifically designed to inspect and automate a real browser, increasing the chance of accidental access to sensitive data.
The skill instructs users to run npx chrome-devtools-mcp without a pinned version, which can pull the latest package at execution time. That creates a supply-chain risk: a malicious or compromised upstream release could be fetched and executed automatically in the user's environment.
The installation command uses an unpinned package reference (npx chrome-devtools-mcp@latest / effectively latest resolution), which allows future upstream package changes or a compromised publish to be pulled at install time. Because this MCP server is intended to control a real browser from an AI tool, a malicious update could gain broad access to browsing sessions, page content, cookies, screenshots, and local workflow context.
The verification flow instructs users to let the AI open a live browser page and capture screenshots, but it does not clearly warn that browser control can expose page contents, authenticated sessions, console data, or sensitive information visible in tabs. In the context of an AI-integrated browser-control MCP, this omission increases the chance that users test the feature against non-public content without understanding the privacy implications.
The documentation advertises visibility into full request URLs, headers, and response bodies without any warning about sensitive data exposure. Network traces commonly contain API keys, bearer tokens, session identifiers, PII, and confidential business data, so encouraging unrestricted inspection increases the chance an agent exfiltrates or unnecessarily processes secrets.
The browser automation example includes entering a username and password directly in the prompt, normalizing the practice of placing credentials into agent-visible instructions. In an AI/browser automation environment, this can cause credentials to be logged, retained in transcripts, or exposed to connected tools and debugging artifacts.
The guide explicitly instructs the agent to execute JavaScript that reads window.localStorage.getItem('user_token'), which is a direct credential/token extraction pattern. In the context of an AI-controlled browser debugging skill, this extends beyond ordinary diagnostics into accessing secrets that could authenticate as the user against backend services.
The documentation explicitly recommends connecting the tool to an already running Chrome instance for debugging logged-in pages or a specific browser profile, but it does not warn that the MCP server can then access highly sensitive session context. In this skill’s context, that is materially risky because the exposed tools include navigation, JavaScript evaluation, network inspection, console access, screenshots, and typing/clicking, which together can read or manipulate authenticated content and profile data.
SQP-3 applies to all file types and prohibits natural-language policy violations such as forcing a specific language without opt-in. This file presents all operational instructions in Chinese and does not offer an alternative language, language selection, or documented region-specific justification.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Using npx -y chrome-devtools-mcp@latest --headless executes the latest package version at runtime, which creates a supply-chain trust risk: a compromised upstream release or dependency could run arbitrary code on the user's machine. In the context of an MCP/browser-control tool, that code would run with the user's local privileges and could also access browser automation capabilities, making the impact more serious than a normal CLI utility.
claude mcp add chrome-devtools --scope user npx chrome-devtools-mcp@latest configures the agent to launch an unpinned package from the registry. That means future executions may silently pull changed code, enabling arbitrary code execution via a malicious or hijacked package release and persisting that risk in the agent configuration.
This markdown file includes a destructive operational step (pkill -f "Google Chrome") that can abruptly close all Chrome windows and interrupt unsaved work. Under SQP-2 for markdown files, actions that may affect user data or system state should include a user warning, but no such warning is present here.
The manual test command npx -y chrome-devtools-mcp@latest --headless again relies on an unpinned latest package, exposing users to registry and dependency compromise at execution time. Because this tool controls Chrome DevTools, compromise could enable browser interaction, local data access through the browser context, or misuse of authenticated sessions.
Natural-language policy requires flagging cases where a skill forces a specific language without user opt-in. This installation guide appears fully Chinese-language and does not indicate that other language options are available or that the locale restriction is intentional and justified.
SQP-3 适用于所有文件,包含自然语言中的语言/locale 政策问题。该文档标题及全文均固定为中文,未见提供用户语言选项、双语说明或对语言限制的合理化说明,可能与要求用户可选择语言/locale 的组织政策不一致。
No suspicious patterns detected.