T08 · Insecure Dependencies
- Location
references/setup.md:5- Finding
Unpinned Mutable Source Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
references/setup.md, lines 5–12
Vulnerability Type: Supply-chain risk from an unpinned source dependency
Risk Level: MediumVulnerable Code
bash Webwright is distributed from source (MIT, https://github.com/microsoft/webwright): git clone https://github.com/microsoft/webwright cd webwright python3 -m venv .venv && source .venv/bin/activate # recommended: isolate the install pip install -e . playwright install chromiumTechnical Analysis
The setup procedure clones the mutable default branch of the declared Microsoft Webwright repository and installs it in editable mode without pinning a reviewed release or commit. It also provides no source-integrity verification and does not lock the transitive Python dependencies resolved during installation.
Although the repository URL is consistent with the Skill's declared upstream project and no malicious package or typosquatted source was identified, the effective code installed by this procedure can change after the Skill itself has been reviewed. A compromised upstream repository, malicious default-branch update, or dependency compromise could therefore introduce executable code that was not present during this audit.
A virtual environment limits dependency conflicts but does not create a security boundary. Installation hooks and the installed CLI execute with the invoking user's operating-system privileges.
Attack Path
- The upstream repository's default branch, release process, or dependency metadata is compromised or receives a malicious change.
- A user follows the documented setup procedure at a later time.
git cloneretrieves the then-current, unreviewed default-branch contents.pip install -e .processes and installs that mutable source and its dependencies.- Malicious installation logic may execute during installation, or malicious runtime logic may execute when
webwright doctororwebwright mainis invoked.
...[truncated 732 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin Webwright to a reviewed release tag and, preferably, verify the corresponding full commit SHA before installation.
- Publish the exact supported version in the setup guide rather than cloning the mutable default branch.
- Use a non-editable installation for normal use, reserving
pip install -e .for development environments. - Verify release artifacts or source archives with trusted checksums or signatures.
- Lock direct and transitive Python dependencies with hashes, and install them using hash enforcement where supported.
- Document a controlled upgrade process requiring review and testing before changing the pinned Webwright revision.
- Continue using an isolated virtual environment and run browser automation under a non-privileged account with access limited to the required workspace and credentials.
