Paper Reveals MCP Skills Chain Attacks That Bypass Permission Checks
Understand the story
In October 2026, a paper pointed out that MCP's Skills mechanism is vulnerable to chain attacks: an attacker can combine multiple Skills to bypass the permission checks of any single Skill. On October 6, an author on DEV Community published a roughly 100-line Python checker called chain_check.py that uses two rules to detect this kind of chained Skill approval hijacking. The single-Skill rule flags any Skill whose text contains both a state-changing action (upload, send, delete, transfer) and an approval declaration. The chain rule builds a write-read graph across installed Skills and flags paths where A writes to a file containing an approval declaration and B reads it and then performs a state-changing action. So far, progress is still limited to detection tooling—no official fix or platform-side response has appeared.
Generated by AI from reports · Updated 7 hours ago
Report timeline
Follow the reports to explore different perspectives.
- DEV Community · MCP用 100 行 Python 检查器识别链式 Skill 审批劫持
作者用标准库 Python 写了一个约 100 行的 chain_check.py,用两条规则检测链式 Skill 审批劫持:单 Skill 规则标记同一文本中同时出现状态变更动作(upload、send、delete、transfer)和审批声明的 Skill,链式规则在已安装 Skill 间构建写读图,标记 A 写入含审批声明的文件、B 读取后执行状态变更动作的路径。
Interest in this story
Current interest 8·Peak within comparable coverage 10(Oct 6, 18:00)·Change over 24 hours within comparable coverage –
The trend compares the same participants under continuous, complete observation, so its coverage may be narrower than the current score. Hover or tap to view hourly interest; use the left and right arrow keys to navigate.