T08 · Insecure Dependencies
- Location
SKILL.md:68- Finding
Unpinned Global Installation of Third-Party Packages and System Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:68-80
Vulnerability Type: Supply-chain exposure through unpinned third-party installations
Risk Level: MediumVulnerable Code
bash npm install -g agent-browser agent-browser install --with-deps agent-browser --versionOptional ecosystem install:
bash clawhub install openclaw-skills-browserautomation-skillTechnical Analysis
The installation instructions retrieve the latest available versions of
agent-browser, its browser or system dependencies, and an optional ClawHub package without specifying immutable versions or integrity hashes. The global npm installation may also execute package lifecycle scripts under the invoking user's account.The
agent-browser install --with-depscommand increases the installation scope by requesting browser and operating-system dependencies. Depending on the environment and package implementation, this step may require elevated privileges. The skill does not document a trusted publisher, reviewed version, registry restriction, checksum, signature, or reproducible dependency manifest.This does not establish that the named packages are malicious. It creates a supply-chain weakness in which the software installed during a future invocation can differ from the software originally reviewed.
Attack Path
- An attacker compromises an upstream package, publisher account, registry resolution path, or transitive dependency.
- A malicious or compromised release becomes the version selected by the unpinned installation commands.
- A user follows the skill instructions and runs the global npm or ecosystem installation.
- Package lifecycle code or installed components execute with the user's privileges.
- If system dependency installation is authorized with elevated privileges, the compromise may extend to privileged files or system components.
Impact Assessment
Successful exploitation ...[truncated 461 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every package to a reviewed, exact version instead of installing the latest release.
- Document the expected publisher, official registry, package digest, and signature-verification procedure.
- Use a project-local installation and a lockfile rather than a global npm installation where practical.
- Disable package lifecycle scripts during installation unless they are required and have been reviewed.
- Separate browser installation from operating-system dependency installation so elevated privileges are not granted to an opaque combined operation.
- Review and pin transitive dependencies or use a verified artifact repository.
- Add a verification step that compares downloaded artifacts against published cryptographic checksums.
- Remove the optional ClawHub installation instruction unless the package source, version, and integrity controls are explicitly documented.
