T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned MCP Dependency Allows Mutable Third-Party Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16-20
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: HighVulnerable Code
json "chrome-devtools": { "type": "local", "command": ["npx", "-y", "chrome-devtools-mcp@latest"] }Technical Analysis
The recommended MCP configuration invokes
npxwith both the mutable@latestversion tag and the automatic-confirmation option-y. When a user follows this setup instruction,npxmay download and execute whichever package version the registry currently associates withlatest, without interactive confirmation.Because the dependency is not pinned to a reviewed version and no lockfile or integrity digest is specified, the effective executable payload can change after the Skill has been audited. This creates a supply-chain trust boundary in which compromise of the package publisher, package registry, or publication process could result in arbitrary third-party code being executed on the MCP host.
Attack Path
- An attacker compromises the
chrome-devtools-mcppublisher account, package publication pipeline, or another relevant supply-chain component. - The attacker publishes a malicious package version and causes it to be selected by the
latesttag. - A user follows the configuration instructions in
SKILL.md. npx -y chrome-devtools-mcp@latestretrieves the attacker-controlled version without requesting confirmation.- The malicious package executes locally with the permissions of the user running the MCP server.
- The payload can access resources available to that user and establish additional malicious behavior subject to the host's operating-system controls.
Impact Assessment
Successful exploitation permits arbitrary code execution with the privileges of the MCP host user. Depending on the environment, this could expose readable project files, browser profiles ...[truncated 435 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Replace
@latestwith an exact version that has been reviewed and approved, for example:json "chrome-devtools": { "type": "local", "command": ["npx", "chrome-devtools-mcp@1.2.3"] } -
Replace the example version with the actual vetted release; do not use a range, tag, or floating version.
-
Remove
-ywhere practical so unexpected installation or resolution behavior requires explicit approval. -
Prefer a controlled installation process backed by a committed lockfile and package-manager integrity metadata rather than downloading the dependency dynamically on every invocation.
-
Verify package provenance, publisher identity, release signatures or attestations, and registry integrity before approving upgrades.
-
Establish a documented dependency-update process that reviews changelogs and package contents before changing the pinned version.
-
Run the MCP server under a dedicated, least-privileged account or sandbox with restricted filesystem, credential, browser-profile, and network access to limit the impact of a compromised dependency.
-
