Skip to content
Trending storyUpdating

Paper Reveals MCP Skills Chain Attacks That Bypass Permission Checks

1 report1 reporting sourceUpdated 8 hours ago

Understand the story

AI synthesis

In October 2026, a paper pointed out that MCP's Skills mechanism is vulnerable to chain attacks: an attacker can combine multiple Skills to bypass the permission checks of any single Skill. On October 6, an author on DEV Community published a roughly 100-line Python checker called chain_check.py that uses two rules to detect this kind of chained Skill approval hijacking. The single-Skill rule flags any Skill whose text contains both a state-changing action (upload, send, delete, transfer) and an approval declaration. The chain rule builds a write-read graph across installed Skills and flags paths where A writes to a file containing an approval declaration and B reads it and then performs a state-changing action. So far, progress is still limited to detection tooling—no official fix or platform-side response has appeared.

Generated by AI from reports · Updated 7 hours ago

Report timeline

Follow the reports to explore different perspectives.

10/6
  1. DEV Community · MCP
    用 100 行 Python 检查器识别链式 Skill 审批劫持

    作者用标准库 Python 写了一个约 100 行的 chain_check.py,用两条规则检测链式 Skill 审批劫持:单 Skill 规则标记同一文本中同时出现状态变更动作(upload、send、delete、transfer)和审批声明的 Skill,链式规则在已安装 Skill 间构建写读图,标记 A 写入含审批声明的文件、B 读取后执行状态变更动作的路径。

Interest in this story

Current interest 8·Peak within comparable coverage 10(Oct 6, 18:00)·Change over 24 hours within comparable coverage –

02.557.51010/618:0010/620:0010/622:0010/700:00

The trend compares the same participants under continuous, complete observation, so its coverage may be narrower than the current score. Hover or tap to view hourly interest; use the left and right arrow keys to navigate.