Back to skill

Security audit

Web Perf

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for web performance auditing, but its setup asks users to run a mutable third-party MCP package locally via npx without pinning a reviewed version.

Install only if you are comfortable adding a local Chrome DevTools MCP server. Prefer pinning chrome-devtools-mcp to a specific reviewed version, avoid auto-confirming installs where practical, and run the MCP server with the least local and browser access needed for the audit.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:16
Finding

Unpinned MCP Dependency Allows Mutable Third-Party Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16-20
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: High

Vulnerable Code

json
"chrome-devtools": {
  "type": "local",
  "command": ["npx", "-y", "chrome-devtools-mcp@latest"]
}

Technical Analysis

The recommended MCP configuration invokes npx with both the mutable @latest version tag and the automatic-confirmation option -y. When a user follows this setup instruction, npx may download and execute whichever package version the registry currently associates with latest, without interactive confirmation.

Because the dependency is not pinned to a reviewed version and no lockfile or integrity digest is specified, the effective executable payload can change after the Skill has been audited. This creates a supply-chain trust boundary in which compromise of the package publisher, package registry, or publication process could result in arbitrary third-party code being executed on the MCP host.

Attack Path

  1. An attacker compromises the chrome-devtools-mcp publisher account, package publication pipeline, or another relevant supply-chain component.
  2. The attacker publishes a malicious package version and causes it to be selected by the latest tag.
  3. A user follows the configuration instructions in SKILL.md.
  4. npx -y chrome-devtools-mcp@latest retrieves the attacker-controlled version without requesting confirmation.
  5. The malicious package executes locally with the permissions of the user running the MCP server.
  6. The payload can access resources available to that user and establish additional malicious behavior subject to the host's operating-system controls.

Impact Assessment

Successful exploitation permits arbitrary code execution with the privileges of the MCP host user. Depending on the environment, this could expose readable project files, browser profiles ...[truncated 435 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact version that has been reviewed and approved, for example:

    json
    "chrome-devtools": {
      "type": "local",
      "command": ["npx", "chrome-devtools-mcp@1.2.3"]
    }
    
  2. Replace the example version with the actual vetted release; do not use a range, tag, or floating version.

  3. Remove -y where practical so unexpected installation or resolution behavior requires explicit approval.

  4. Prefer a controlled installation process backed by a committed lockfile and package-manager integrity metadata rather than downloading the dependency dynamically on every invocation.

  5. Verify package provenance, publisher identity, release signatures or attestations, and registry integrity before approving upgrades.

  6. Establish a documented dependency-update process that reviews changelogs and package contents before changing the pinned version.

  7. Run the MCP server under a dedicated, least-privileged account or sandbox with restricted filesystem, credential, browser-profile, and network access to limit the impact of a compromised dependency.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.