T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party Package Installation and Mutable Source Build
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16-31;CONTRIBUTING.md:22-26
Vulnerability Type: Supply-chain exposure through unpinned dependencies and mutable sources
Risk Level: MediumVulnerable Code
SKILL.md:16-31:bash ## Installation ### npm recommended ```bash npm install -g agent-browser agent-browser install agent-browser install --with-depsFrom Source
bash git clone https://github.com/vercel-labs/agent-browser cd agent-browser pnpm install pnpm buildtext `CONTRIBUTING.md:22-26`: ```bash 1. Install the latest version ```bash npm install -g agent-browser@latest ```Technical Analysis
The documented installation procedures retrieve and execute third-party software without pinning a reviewed package version, source commit, or integrity digest.
npm install -g agent-browserresolves the package version at installation time, whileagent-browser@latestexplicitly tracks a mutable distribution tag. The source-build procedure similarly clones the repository's mutable default branch.Package installation can execute npm lifecycle scripts from the package or its transitive dependencies. The source workflow also runs dependency installation and build logic from content that may have changed after this Skill was reviewed. Installing the npm package globally makes its executable available throughout the user's environment and may increase the consequences of a supply-chain compromise.
No evidence establishes that the current upstream package or repository is malicious. The vulnerability is the absence of controls ensuring that users install the same reviewed artifact.
Attack Path
- An attacker compromises the upstream package, a maintainer account, the source repository, or a transitive dependency.
- The attacker publishes a malicious release under the
latesttag or modifies the repository's default branch.
...[truncated 778 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto a specifically reviewed version rather than using an implicit current version or@latest. - Pin source installations to a full reviewed commit hash or signed release tag.
- Publish and verify expected integrity hashes or signatures for downloaded artifacts.
- Use a committed lockfile and frozen-lockfile installation mode for source builds.
- Review lifecycle scripts and dependency changes before upgrading.
- Prefer a project-local, least-privilege installation over a global installation where practical.
- Document that users should not run installation commands with administrative privileges unless strictly required.
- Establish a controlled upgrade process that reviews and tests each new upstream version before updating the pinned reference.
- Pin
