T08 · Insecure Dependencies
- Location
SKILL.md:194- Finding
Unpinned Global Installation of Third-Party Browser Automation Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 194-199
Vulnerability Type: Unverified and mutable third-party dependency installation
Risk Level: HighVulnerable Code Snippet:
markdown ## Installation ```bash npm install -g agent-browser agent-browser install # Download Chromium agent-browser install --with-deps # Linux: + system depstext ### Technical Analysis The installation instructions globally install `agent-browser` without specifying a reviewed version, integrity digest, lockfile, signature, or other artifact-verification mechanism. The subsequently installed CLI is also instructed to download Chromium and, when `--with-deps` is used, install additional system dependencies. Because the package reference is mutable, the code installed when a user follows these instructions may differ from the code that existed when the Skill was audited. Linking to a GitHub homepage elsewhere in the document does not cryptographically verify that the package retrieved from the npm registry corresponds to the reviewed repository or commit. Global installation increases the affected scope compared with a project-local dependency. Depending on the operating environment and how system dependencies are installed, the `--with-deps` operation may also request or use elevated system permissions. ### Attack Path 1. An attacker compromises the dependency publisher, npm account, registry distribution channel, or a downstream installation component. 2. The attacker publishes or substitutes a malicious version under the expected package name. 3. A user follows the Skill instructions and runs `npm install -g agent-browser` without a pinned version or integrity validation. 4. The mutable package is installed globally and its installation hooks or executable code run with the invoking user's permissions. 5. The installed CLI may then access local files, browser sessions, auth ...[truncated 582 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto an explicitly reviewed version rather than installing the latest mutable release. - Record and verify the expected package integrity digest or signature before installation.
- Document the trusted npm registry, expected publisher identity, source repository, and reviewed source commit.
- Prefer a project-local installation with a committed lockfile over a global installation.
- Disable or separately review package lifecycle scripts where operationally possible.
- Pin and verify the Chromium release downloaded by the CLI.
- Review system dependencies separately and avoid
--with-depsunless required. - Perform installation under a non-administrative account or in a sandboxed container with minimal filesystem and network access.
- Pin
