T08 · Insecure Dependencies
- Location
references/agent-browser-overview.md:8- Finding
Unpinned Third-Party Package Execution and Dynamic Runtime Downloads
- Content
View full analysis
Vulnerability Details
File Location:
references/agent-browser-overview.md:8-17; repeated installation guidance appears inreferences/agent-browser-troubleshooting.md:3-5
Vulnerability Type: Supply-chain risk from unpinned dependencies and dynamically downloaded components
Risk Level: MediumVulnerable Code Snippet:
markdown ## 2) Install and setup (hardened) - Pin the version you trust: - `npm install -g agent-browser@<version>` - Prefer a dedicated environment or container for installs. - Avoid running with elevated OS privileges. - Install browser runtime: - `agent-browser install` - Linux dependencies (if needed): - `agent-browser install --with-deps` - or `npx playwright install-deps chromium`The troubleshooting guide repeats commands that retrieve browser artifacts or system dependencies:
markdown ## CLI runs but no browser opens - Run `agent-browser install` to download Chromium. - On Linux, run `agent-browser install --with-deps` if dependencies are missing.Technical Analysis
The documentation recommends pinning
agent-browser, but supplies only the placeholder<version>rather than an audited exact version. It also invokesnpx playwrightwithout specifying a version. Depending on the local npm configuration and cache,npxmay retrieve and execute a package from a remote registry at invocation time.The
agent-browser install,agent-browser install --with-deps, andplaywright install-depsoperations retrieve external artifacts or install host dependencies. No lockfile, integrity digest, verified download source, or trusted-registry configuration is provided. Consequently, the effective code and artifacts installed can differ from those reviewed with this Skill.This is a supply-chain weakness rather than evidence that the current documentation or package contains an intentionally malicious payload. The project does include ...[truncated 1711 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
agent-browser@<version>with a reviewed, exact version rather than a range, tag, or placeholder. - Pin Playwright explicitly, for example by using
npm exec --package=playwright@<audited-exact-version> -- playwright install-deps chromium. - Provide and enforce a lockfile for all Node.js dependencies and require lockfile-based installation where applicable.
- Verify package integrity using registry integrity metadata, trusted checksums, signatures, or provenance attestations.
- Explicitly configure the expected official package registry and reject unexpected registry overrides.
- Pin and verify downloaded browser-runtime artifacts where the tooling supports checksum or signature validation.
- Perform installation and browser automation in a disposable, non-root container or similarly isolated environment with minimal filesystem and network access.
- Avoid global installation when possible; prefer a project-local, locked dependency or an isolated tool environment.
- Separate browser-runtime installation from operating-system dependency installation, and require explicit human approval before any command that changes system packages.
- Document the exact trusted versions, artifact sources, hashes, and upgrade-review process so installation is reproducible.
- Replace
