T09 · Insecure Skill Coding Practices
- Location
SKILL.md:263- Finding
Overbroad Process Termination Can Disrupt Unrelated Browser Automation Sessions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:263
Vulnerability Type: Overbroad process termination
Risk Level: MediumComplete Code Snippet:
markdown - **Zombie Browsers:** If the DevTools server fails with a lock error, run `pkill -f "chrome-devtools-mcp" || true`.Technical Analysis
The Skill recommends using
pkill -f, which matches the supplied pattern against complete process command lines and terminates every accessible matching process. It does not verify that a process owns the relevant lock, belongs to the current Skill invocation, or is actually stale.This violates least-scope process-management practices. A lock problem affecting one browser profile does not require terminating all
chrome-devtools-mcpinstances owned by the executing user. The appended|| truealso suppresses failure status, potentially concealing an unsuccessful or partially successful cleanup operation.The behavior is local and does not provide evidence of privilege escalation beyond the permissions already held by the Agent. Nevertheless, it can terminate unrelated processes within that existing user context.
Attack Path
- A Chrome DevTools MCP operation reports a lock error, whether from a genuinely stale process or an active concurrent session.
- The Agent follows the troubleshooting instruction in
SKILL.md. pkill -fenumerates processes whose complete command lines containchrome-devtools-mcp.- Every matching process that the Agent's operating-system identity is permitted to signal is terminated.
- Unrelated browser-automation sessions are interrupted, and their transient or unsaved state may be lost.
- Because
|| trueforces a successful shell status, the workflow may continue without accurately reporting cleanup failures.
Impact Assessment
The impact is limited to processes the executing identity is already authorized to signal; this command does not itself acquire ...[truncated 584 chars]
- Remediation
View remediation
Remediation Suggestions
Replace the global command-line-pattern kill with narrowly scoped cleanup:
- Determine the exact browser profile or lock file involved in the reported error.
- Resolve the PID associated with that specific lock or the process started by the current Skill invocation.
- Validate the PID's owner, full command line, start time, and relationship to the current task before signaling it.
- Ask for explicit user confirmation before terminating a process not launched by the current invocation.
- Send
SIGTERMto the validated PID and allow a bounded grace period before consideringSIGKILL. - Check and report the termination result instead of masking every error with
|| true. - Prefer graceful shutdown through the MCP server's lifecycle API when such an API is available.
- If no ownership-safe process identification is possible, instruct the user to inspect active sessions manually rather than executing a broad
pkill -fcommand.
