T08 · Insecure Dependencies
- Location
SKILL.md:197- Finding
Unpinned Global Dependency Installation and Unverified Secondary Downloads
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 197-199
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code:
bash npm install -g agent-browser agent-browser install # Download Chromium agent-browser install --with-deps # Linux: + system depsTechnical Analysis
The installation instructions globally install
agent-browserwithout pinning an exact package version or verifying package integrity. Consequently, the code installed and executed can change after this Skill has been reviewed, even though the Skill package itself remains unchanged.The newly installed CLI is then trusted to download Chromium. The
--with-depsoption may also install operating-system dependencies, potentially under elevated privileges. No version constraints, lockfile, cryptographic checksums, trusted artifact locations, or post-download verification procedures are provided.This creates a third-party supply-chain exposure. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream change could cause installation-time lifecycle scripts or CLI commands to execute attacker-controlled code.
Attack Path
- An attacker compromises the upstream npm package, its publisher account, release pipeline, or a dependency included in a future release.
- The attacker publishes a modified version under the expected package name.
- A user follows
SKILL.mdand runsnpm install -g agent-browserwithout an exact version constraint. - npm resolves the current package release and executes any applicable installation lifecycle code.
- The user runs
agent-browser installoragent-browser install --with-deps. - The compromised CLI downloads or installs additional attacker-controlled components.
- The malicious code executes with the privileges of the invoking user or, where elevated system dependency instal ...[truncated 632 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto an exact reviewed version rather than relying on the latest registry release. - Prefer a project-local installation governed by a committed lockfile instead of a global installation.
- Use npm integrity metadata and a reproducible installation method such as
npm ciwhere applicable. - Document the expected official registry, package publisher, repository, and release provenance.
- Verify downloaded Chromium artifacts using vendor-provided cryptographic checksums or signatures.
- Pin the Chromium revision and system dependency versions where supported.
- Review package lifecycle scripts and transitive dependencies before approving upgrades.
- Run installation in a sandbox, container, or other least-privilege environment.
- Avoid
--with-depsunless it is necessary. Clearly disclose any administrative privileges it requires and provide a reviewed list of system packages that it installs. - Establish an explicit dependency update and security-review process so upstream changes are not adopted automatically.
- Pin
