Back to skill

Security audit

Browser Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned browser automation, but it gives AI access to a real Chrome profile and login sessions through persistent, unpinned components without enough safeguards.

Install only if you trust the maintainer and are comfortable giving an AI-connected tool access to your real Chrome session. Prefer a dedicated Chrome profile with no unrelated logins, saved passwords, history, or bookmarks; pin and verify exact bridge and extension versions; review extension permissions; and require confirmation before cookie-backed requests, network capture, history searches, bookmark deletion, or actions on logged-in sites.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:26
Finding

Unpinned npm Package Is Installed and Executed with Broad Browser Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-29 and 65-66
Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

Vulnerable Code

bash
npm install -g mcp-chrome-bridger
# or
pnpm install -g mcp-chrome-bridger
mcp-chrome-bridger register

The alternative STDIO configuration also executes the package through npx:

json
"command": "npx",
"args": ["mcp-chrome-bridger", "stdio"]

Technical Analysis

The installation instructions do not pin mcp-chrome-bridger to a reviewed version, integrity hash, or immutable artifact. Consequently, the code installed depends on whichever package version the npm registry resolves at installation time.

Global installation increases exposure because package installation scripts and executables run in the user's environment and may remain available to other processes. The npx configuration presents a similar risk: when the package is not already available locally, npx may retrieve and execute registry-hosted code at runtime. The effective code can therefore change after the Skill has been audited.

The dependency is particularly sensitive because the documented bridge is intended to interact with an existing Chrome profile. Its declared capabilities include reading page content and browsing history, capturing screenshots and network traffic, modifying bookmarks, controlling browser interactions, and sending requests with browser cookies.

No evidence in the reviewed file proves that the current npm package is malicious. The vulnerability is the absence of version, integrity, and provenance controls for a dependency receiving highly sensitive browser access.

Attack Path

  1. An attacker compromises the npm publisher account, takes control of the package, or causes users to resolve a malicious future release.
  2. The attacker publishes a modified mcp-chrome-bridger package under the expected package name.
  3. A user f ...[truncated 1252 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm dependency to an exact reviewed version, rather than relying on the latest registry resolution:
    bash
    npm install --save-exact mcp-chrome-bridger@<reviewed-version>
    
  2. Install the package locally within a controlled project instead of globally.
  3. Commit and enforce a lockfile with integrity metadata.
  4. Replace runtime package retrieval with local-only execution, such as npx --no-install mcp-chrome-bridger stdio, after installing and verifying the pinned dependency.
  5. Verify package provenance, publisher identity, release signatures, and registry integrity metadata before installation.
  6. Audit package installation scripts and transitive dependencies for every upgrade.
  7. Run the bridge under a dedicated, restricted operating-system account or sandbox.
  8. Use a separate browser profile containing no unrelated sessions, history, bookmarks, or stored credentials.
  9. Restrict the extension and bridge to the minimum required hosts and capabilities.
  10. Establish an explicit upgrade process in which new package versions are reviewed and tested before deployment.

T08 · Insecure Dependencies

Error
Location
SKILL.md:34
Finding

Unverified Chrome Extension Release Is Loaded in Developer Mode

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34-40
Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

Vulnerable Code

text
Download from [GitHub Releases](https://github.com/femto/mcp-chrome/releases):

1. Download `mcp-chrome-extension-vX.X.X.zip`
2. Open Chrome → `chrome://extensions/`
3. Enable "Developer mode"
4. Click "Load unpacked" and select the extracted folder
5. Click the extension icon → Click "Connect"

Technical Analysis

The instructions direct users to download an unspecified extension version from a mutable GitHub Releases page and load it as an unpacked extension in Chrome Developer mode. They provide no exact version, commit identifier, cryptographic checksum, digital signature, reproducible-build verification procedure, or expected extension identifier.

Loading an unpacked extension bypasses the normal Chrome Web Store distribution and review channel. If the release account, repository, downloadable archive, or delivery path is compromised, users may install altered extension code without a reliable mechanism for detecting the substitution.

This risk is amplified by the extension's declared purpose: connecting AI clients to the user's existing Chrome browser and login sessions. An altered extension may be able to observe or manipulate content and actions within the permissions declared in its manifest.

The reviewed file does not establish that the referenced repository or current extension release is malicious. The finding concerns unsafe acquisition and verification practices for a privileged browser component.

Attack Path

  1. An attacker compromises the GitHub repository, maintainer account, release workflow, or release archive.
  2. The attacker replaces or publishes an extension ZIP containing malicious JavaScript or an overprivileged manifest.
  3. A user follows the Skill instructions and selects an arbitrary current release because no ...[truncated 1112 chars]
Remediation
View remediation

Remediation Suggestions

  1. Specify an exact, audited extension version and immutable release URL.
  2. Publish a SHA-256 checksum for the archive through a separately protected and authenticated channel.
  3. Digitally sign releases and require users to verify the signature before extraction or installation.
  4. Identify the expected source commit and provide reproducible-build instructions so the archive can be compared with source.
  5. Prefer a verified Chrome Web Store distribution when feasible, while retaining independent integrity and publisher checks.
  6. Document the expected extension ID, manifest permissions, and file hashes so users can detect substitution or permission expansion.
  7. Minimize requested permissions, use narrow host allowlists, and make sensitive capabilities opt-in.
  8. Use a dedicated Chrome automation profile without unrelated login sessions, saved passwords, history, or personal extensions.
  9. Add explicit confirmation gates for history access, network capture, screenshots, bookmark changes, and cookie-authenticated requests.
  10. Review every extension update before deployment rather than instructing users to install an unspecified latest release.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly states that it works with the user's existing Chrome browser and login sessions, and exposes tools for history search, bookmark management, content extraction, network capture, and requests with browser cookies, but it does not warn users about these sensitive access levels. This omission is dangerous because users may unknowingly authorize actions that expose private data or perform authenticated operations across websites.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation language is broad enough to invoke this skill for many generic browsing tasks, increasing the chance that an agent routes ordinary web requests into a capability that can control the user's real Chrome session. In this context, that is risky because the skill can access authenticated tabs, browsing history, bookmarks, page contents, and perform actions on behalf of the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.