T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Unpinned npm Package Is Installed and Executed with Broad Browser Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-29 and 65-66
Vulnerability Type:T08: Insecure Dependencies
Risk Level: HighVulnerable Code
bash npm install -g mcp-chrome-bridger # or pnpm install -g mcp-chrome-bridger mcp-chrome-bridger registerThe alternative STDIO configuration also executes the package through
npx:json "command": "npx", "args": ["mcp-chrome-bridger", "stdio"]Technical Analysis
The installation instructions do not pin
mcp-chrome-bridgerto a reviewed version, integrity hash, or immutable artifact. Consequently, the code installed depends on whichever package version the npm registry resolves at installation time.Global installation increases exposure because package installation scripts and executables run in the user's environment and may remain available to other processes. The
npxconfiguration presents a similar risk: when the package is not already available locally,npxmay retrieve and execute registry-hosted code at runtime. The effective code can therefore change after the Skill has been audited.The dependency is particularly sensitive because the documented bridge is intended to interact with an existing Chrome profile. Its declared capabilities include reading page content and browsing history, capturing screenshots and network traffic, modifying bookmarks, controlling browser interactions, and sending requests with browser cookies.
No evidence in the reviewed file proves that the current npm package is malicious. The vulnerability is the absence of version, integrity, and provenance controls for a dependency receiving highly sensitive browser access.
Attack Path
- An attacker compromises the npm publisher account, takes control of the package, or causes users to resolve a malicious future release.
- The attacker publishes a modified
mcp-chrome-bridgerpackage under the expected package name. - A user f ...[truncated 1252 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the npm dependency to an exact reviewed version, rather than relying on the latest registry resolution:
bash npm install --save-exact mcp-chrome-bridger@<reviewed-version> - Install the package locally within a controlled project instead of globally.
- Commit and enforce a lockfile with integrity metadata.
- Replace runtime package retrieval with local-only execution, such as
npx --no-install mcp-chrome-bridger stdio, after installing and verifying the pinned dependency. - Verify package provenance, publisher identity, release signatures, and registry integrity metadata before installation.
- Audit package installation scripts and transitive dependencies for every upgrade.
- Run the bridge under a dedicated, restricted operating-system account or sandbox.
- Use a separate browser profile containing no unrelated sessions, history, bookmarks, or stored credentials.
- Restrict the extension and bridge to the minimum required hosts and capabilities.
- Establish an explicit upgrade process in which new package versions are reviewed and tested before deployment.
- Pin the npm dependency to an exact reviewed version, rather than relying on the latest registry resolution:
