前端进阶之旅前端进阶之旅
基础篇
进阶篇
高频篇
精选篇
手写篇
面经篇
AI 篇
原理篇
每日一题
小程序题库
知识卡片NEW
  • 历年面经按年份追踪真实考点
  • 算法题库NEW在线编码即时判题
  • 专项自测100 题快速查漏
  • 业务场景题真实业务问题与追问
  • 查漏补缺常见问题解析
  • AI 模拟面试NEW模拟真实面试 + 报告
  • 前端基础
    • HTTP从报文一路讲到 HTTPS
    • 浏览器渲染、事件循环、进程
    • 计算机基础Linux、网络、操作系统
  • 进阶专项
    • 设计模式23 种模式怎么用
    • 前端系统进阶学习大型项目工程化
    • 前端综合文章长期沉淀的实践文
  • 工程与工具
    • Node学习指南从环境搭建到服务端
    • NPM工作流script、依赖与发布
    • Docker容器化部署上手
    • Canvas图形与动画实战
  • 路线与导图
    • 思维导图知识点全景图
    • 学习路线按图索骥不跑偏
    • AI 定制路线NEW按你的简历现排
    • AI 知识地图NEW串起全站知识点
  • 动态
    • AI 热点NEWAI 每日动态
    • 公众号动态公众号历史文章
    • 博客动态站长的技术博客
    • 开发者导航常用工具与文档站
AI 助手NEW
旧版
基础篇
进阶篇
高频篇
精选篇
手写篇
面经篇
AI 篇
原理篇
每日一题
小程序题库
知识卡片NEW
  • 历年面经按年份追踪真实考点
  • 算法题库NEW在线编码即时判题
  • 专项自测100 题快速查漏
  • 业务场景题真实业务问题与追问
  • 查漏补缺常见问题解析
  • AI 模拟面试NEW模拟真实面试 + 报告
  • 前端基础
    • HTTP从报文一路讲到 HTTPS
    • 浏览器渲染、事件循环、进程
    • 计算机基础Linux、网络、操作系统
  • 进阶专项
    • 设计模式23 种模式怎么用
    • 前端系统进阶学习大型项目工程化
    • 前端综合文章长期沉淀的实践文
  • 工程与工具
    • Node学习指南从环境搭建到服务端
    • NPM工作流script、依赖与发布
    • Docker容器化部署上手
    • Canvas图形与动画实战
  • 路线与导图
    • 思维导图知识点全景图
    • 学习路线按图索骥不跑偏
    • AI 定制路线NEW按你的简历现排
    • AI 知识地图NEW串起全站知识点
  • 动态
    • AI 热点NEWAI 每日动态
    • 公众号动态公众号历史文章
    • 博客动态站长的技术博客
    • 开发者导航常用工具与文档站
AI 助手NEW
旧版
返回 AI 情报前线
All News · 全部资讯8773
  • AI Agent自动化开发者工作流:41%发布周期压缩实战
  • Token末日:Accenture 数据显示非工程师才是 token 消耗大户
  • Cloudflare 推出面向 AI Agent 的浏览器 Kitesurf
  • AI独立生成50次测试用例:49次精准覆盖所有边界条件
  • AI Agent支付基础设施一周内集体企业级化
  • AI Agent 故障隔离实战: blast radius 与三级 kill switch 设计
  • OpenAI发布Astra模型网络安全初步评估报告
  • Claude Code 高级编排:子 Agent 模式与防耗尽策略
  • 用 Spring Boot 搭建自托管 AI 客服组件,零 SaaS 订阅
  • 给 AI 写指令本质是写警告标签
  • Meta 认为编程代理的未来在于持久记忆而非更强模型
  • GitHub Code Quality 不再自动为 PR 添加 Copilot 审阅者
  • 别再往ChatGPT扔错误堆栈了
  • Claude Fable 5单次会话从推文构建可玩3D游戏
  • 让AI Agent拥有支付能力:x402协议实战
  • AI Agent工具优化:让Agent能安全调用你的工具
  • 用 Python + AI 自动化播客元数据流水线
  • AWS上Agentic AI实际成本拆解:单元经济学分析
  • open-connector:让AI Agent永远不接触用户凭证
  • npm脚本骗过多数用户:Agent权限提示研究
  • 警惕:MCP服务器正重蹈npm安全覆辙
  • GitHub Actions触发器丢失需手动恢复,附多条工具快讯
  • 本地语音助手如何做到「即时感」的工程实践
  • SpaceXAI Grok 4.6、OpenAI 免费无限聊、Meta 编程 Agent 入局
  • 子进程清理的正确姿势:terminate 的三个谎言
  • TypeScript 子代理设计指南:何时该分叉,何时该内联
  • LLM 返回 Markdown 而非 JSON 的工程解法
  • AI Agent降级早知道:三大监控指标
  • GraphRAG生产环境实体重复问题及免费修复方案
  • JSON提示词Runner bug验证:200次重跑结论依然显著
  • 传统 API 网关为何无法保护 AI Agent 及解决方案
  • AI Agent 事故响应:滚动消失前应记录的关键数据
  • 字节跳动训练10万亿参数大模型对标Anthropic
  • MasterGo MCP Server 打通设计工具与 IDE:减少上下文切换认知损耗
  • Node.js AI Agent 工具超时:超时机制设计与模型可见性
  • AI助手为何总是答非所问:RAG系统的版本地狱
  • 我在 Claude Code 用了一周十亿 token?97% 是缓存
  • 我把 croniter 移植到 Rust 拿了 228/228,但这个数字什么也证明不了
  • 用代码量化品牌在 AI 搜索引擎中的可见度:GEO 扫分工具
  • 多模态模型的真正瓶颈在最弱编码器
  • Cloudflare 解读 Agent 时代的 Bot 行为评分体系
  • SvelteKit 配置可直接写入 vite.config.js
  • Cloudflare 统一 AI Gateway 与 Workers AI,提供统一路由与计费
  • Cloudflare Radar Researcher:用自然语言探索全球互联网流量数据
  • 在 Claude Code 中使用 Kimi K3 省钱提效
  • Matt Pocock 技能套装安装量突破 54 万次
  • 2026 年 AI 模型格局:主要玩家一览及选型指南
  • 电商从 1 到 1000 单的工程架构演进实战
  • AI Agent 让分布式系统双写问题代价飙升
  • Stack Overflow 流量暴跌 78%,AI 编码助手改变开发问题解决方式
  • Flow Render:用async/await思维重构UI交互
  • 已加载 51 / 8773
8.0
热点
AI SCORE
编程提效2026-08-07 21:56

警惕:MCP服务器正重蹈npm安全覆辙

dev.to · AI#MCP#安全#npm
Editor brief · 编辑速览

文章警告AI工具的MCP服务器生态正在重演npm十年来的安全乱象——无人审查代码来源、权限范围模糊,类似当年curl|bash的危险模式被轻易复制。

文章思维导图
Knowledge map
拖拽缩放
Full translation

完整中文译文

Every week there's a new post recommending an MCP server, a Claude skill, or some agent plugin you should install right now. Screenshot of the output, a line about how it changed their workflow, and the life's saver it has become. Never a word about what the thing actually has access to, who wrote it, or what happens if it's malicious.

We spent almost the last decade learning this lesson the hard way with npm. Typosquatted packages, compromised maintainer accounts, postinstall scripts quietly exfiltrating environment variables. We got better at it: lockfiles, npm audit, dependency scanning in CI, actual policies about what gets approved.

Then AI tooling showed up and all of that discipline evaporated.

The install-first, ask-never culture

Watch how these recommendations actually get made. "Install this MCP server, it lets Claude read your Slack." Cool, what permissions does it request? Nobody says. Who maintains it? Unclear. Is the code even public? Sometimes not.

Compare that to how you'd react if a coworker said "just run this shell script I found on Twitter, it'll set up your dev environment." You wouldn't run it blind. But npx some-mcp-server gets pasted into a terminal with less scrutiny than a curl | bash from a stranger, because it's wrapped in the word "AI" and that makes it feel newer and safer than it actually is.

What you're actually granting

An MCP server isn't a browser extension with a sandboxed permission model. Most of them run as a local process with whatever access your user account has. Filesystem, environment variables, network calls, sometimes direct access to API keys you've stored for other tools.

Claude skills are a mischievous case, because they're easier to review than most tools, mostly a bunch of markdown files with instructions, which makes them feel safer than they are. But some skills ship scripts that get executed on your behalf, with no runtime isolation at all. If one of those scripts reads ~/.aws/credentials and posts it somewhere, nothing about the skill format stops that.

Think about what a genuinely malicious MCP server could do with read access to your codebase and network access. It doesn't need to be dramatic. Slowly exfiltrate .env files during normal use, and you'd have no reason to notice until the bill shows up or you lose access to an account.

The parallel nobody's drawing

This is the same problem the CVE and dependency-scanning ecosystem was built for (btw, check my "Stop Wasting Time on CVEs That Don't Affect You" post), just one layer up. Unmaintained dependencies, unclear provenance, code nobody reads before pulling it into their environment. That ecosystem eventually forced tooling and process around this for regular packages, because enough people got burned.

We're at the "getting burned" phase for AI tooling right now, we just haven't named it yet. A compromised MCP server isn't hypothetical, it's a supply chain attack that happens to route through an LLM's tool-calling instead of your package.json.

A checklist that takes five minutes

Nothing here is clever, that's the point. It's the same discipline you already apply, or should apply, to any dependency.

Read the source before installing. If it's not open, or the repo has twelve stars and one contributor who joined last week, that tells you something.

Check what it actually asks for. Filesystem access, network calls, environment variables. If a tool that just summarizes your calendar also wants write access to your filesystem, that's worth a second look.

Prefer boring and transparent over flashy and opaque. A well-documented MCP server that does one thing well beats one that promises everything and explains none of it.

Pin versions instead of always-latest. Same lesson as any other dependency... an update can quietly change behavior or grab a permission you never signed off on.

Run it isolated first. A throwaway container or VM costs you ten minutes and shows you what the thing actually touches before it gets anywhere near your real machine.

Ask the AI itself. Paste the source, or point it at the repo, and ask what it does, what it can access, and whether anything looks off. Takes thirty seconds and you'd be surprised how often it catches something.

Wrapping up, believe me I'm not an anti-tooling

None of this is an argument against MCP servers, skills, or agent tooling in general. They're genuinely useful, I try the new ones constantly. The argument is against the specific culture of "just install it, trust me" that's formed around AI tooling in a way it never quite did around regular packages.

And it's not just developers falling for it. AI got aimed at everyone, so now the person recommending a "must-have AI tool" isn't always a developer who happens to have a bad take, it's maybe someone with a large amount of followers and non technical context, talking to an audience that has even less. A non-technical person installing something because an influencer said it's a game changer has no way to ask what it's actually reaching into. They're not being careless, they were never given the tools to ask the question.

You wouldn't hand a stranger your Gmail credentials because their tweet had good engagement. Don't do the equivalent because they called it an MCP server instead. And if you're the one explaining these tools to someone less technical, that's exactly the sentence worth passing along.

For further actions, you may consider blocking this person and/or reporting abuse

Original source

本文由 AI 翻译整理自 dev.to · AI,原文版权归原作者所有。

阅读英文原文
上一篇
npm脚本骗过多数用户:Agent权限提示研究
下一篇
GitHub Actions触发器丢失需手动恢复,附多条工具快讯