T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Packages and Browser Components
- Content
View full analysis
- Remediation
View remediation
" ``` 2. Generate and maintain a lockfile containing exact transitive versions and cryptographic hashes. Install with hash enforcement where practical: ```bash python -m pip install --require-hashes -r requirements.lock ``` 3. Use an explicitly trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure. 4. Pin a compatible Playwright version so its expected Chromium revision is deterministic. Document the expected browser revision and validate downloaded artifacts through the verification mechanism supported by the distribution process. 5. Run dependency vulnerability and provenance checks in CI. Review and regenerate the lockfile deliberately when upgrading rather than automatically accepting current releases. 6. Install and run the MCP server in an isolated virtual environment or container under a non-privileged account. Restrict filesystem access, secrets, and network destinations to those required for authorized scraping. 7. Update both `SKILL.md` and `references/mcp-setup.md` so users are not directed to bypass the pinned, integrity-checked installation workflow. ]]>
