T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned Playwright Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 27–33
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Mediumbash # Check available browsers npx playwright install # Or install specific browser npx playwright install chromium npx playwright install firefox npx playwright install webkitTechnical Analysis
The setup instructions invoke
playwrightthroughnpxwithout specifying an exact reviewed package version, requiring a committed lockfile, or preventing network installation. When a trusted local Playwright executable is unavailable,npxmay resolve and download the package from the configured npm registry before executing it.This creates a supply-chain exposure because the code executed depends on registry state and local npm configuration at invocation time rather than a dependency version fixed during review. A compromised package release, maintainer account, registry, mirror, or dependency-resolution configuration could cause attacker-controlled package code to run. The Playwright installation process also retrieves browser artifacts, expanding the externally sourced execution and installation surface.
Attack Path
- A user follows the documented setup instructions on a system without a trusted local Playwright installation.
- The user runs an unpinned command such as
npx playwright install. npxresolves the package using the configured npm registry and current dependency metadata.- An attacker has compromised a resolved package release, dependency, maintainer account, registry path, or configured mirror.
- The malicious package or dependency is downloaded and executed under the invoking user's account.
- The attacker can perform actions permitted to that account while the expected browser installation appears to proceed.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user running
npx. The affected sco ...[truncated 567 chars]- Remediation
View remediation
Remediation Suggestions
- Declare Playwright at an exact reviewed version in a committed package manifest rather than resolving it implicitly:
json { "devDependencies": { "playwright": "1.x.y" } } - Commit the generated lockfile and review dependency changes before upgrades.
- Use
npm ciin clean environments so installation follows the committed lockfile. - Invoke only the installed local executable and prohibit fallback downloads:
bash npm ci npx --no-install playwright install chromium - Pin and authenticate the npm registry configuration, and use registry integrity metadata and dependency scanning.
- Run installation as an unprivileged user in an isolated environment with restricted filesystem access, network access, and credentials.
- Pin or otherwise verify downloaded browser artifacts where supported, and document the expected package and browser versions.
- Declare Playwright at an exact reviewed version in a committed package manifest rather than resolving it implicitly:
