T08 · Insecure Dependencies
- Location
SKILL.md:109- Finding
Unpinned MCP Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This form-filling skill is mostly aligned with its purpose, but it asks the agent to start and control a real Chrome debug session in ways that are too broad and under-scoped for automatic installation.
Install only if you are comfortable letting the skill and its MCP dependency control a Chrome debug session. Prefer a pinned, reviewed MCP package, a dedicated temporary browser profile, explicit approval before launching Chrome or navigating, and clear cleanup that closes the debug browser and removes temporary data after use.
SKILL.md:109Unpinned MCP Package Is Automatically Downloaded and Executed
SKILL.md:29Persistent Unauthenticated Chrome DevTools Endpoint Is Left Running
Launching Chrome via shell is not necessary to the core task of identifying and filling fields once a browser session is available, and it gives the skill host-level process execution behavior. That creates a meaningful boundary break: a form-filling skill should not silently gain the ability to spawn local applications, create profiles, and persist background processes.
The skill is designed to inspect and interact with the user's real Chrome session through CDP, which can expose sensitive page contents, autofilled data, and authenticated context. The documentation does not provide a prominent privacy warning or explain that live browser data from the user's real session will be read and used.
The manifest describes CDP-based form reading/filling, but the documentation additionally instructs the agent to use shell commands to start a local Chrome instance. This is a material capability expansion from browser automation to local process execution, which can affect the host system and user session in ways not disclosed by the skill metadata.
The instructions direct the agent to execute a local process launch command immediately and in the background, without a clear user-facing warning or consent checkpoint. Even if the command only starts Chrome, undisclosed local execution is risky because it changes system state, opens a debug port, and may expose the user's authenticated browser context.
Using nohup to start Chrome in the background with a dedicated profile creates a persistent debugging-capable browser process beyond the immediate interaction. In a real-user environment, persistent debug sessions increase exposure because the remote debugging port and authenticated browser state may remain available longer than intended.
直接执行(后台启动):
nohup /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome \
--remote-debugging-port=9222 \
--user-data-dir="/tmp/chrome_debug_profile" \
> /tmp/chrome_debug.log 2>&1 &
The skill expands its behavior from form-filling into autonomous destination inference and navigation, telling the agent to guess target URLs and browse there without requiring an explicit user-provided link. In the context of a real logged-in Chrome session, this increases the chance of unintended navigation to sensitive sites, phishing lookalikes, or user-confusing actions outside the narrow declared scope.
All user-facing natural-language instructions in the skill are written in Chinese, with no indication that another language can be used or that the locale is intentionally constrained. This can violate language or locale policy when a skill implicitly forces a specific language without user opt-in.
No suspicious patterns detected.