T08 · Insecure Dependencies
- Location
scripts/install.sh:21- Finding
Unpinned Third-Party Dependencies Permit Supply-Chain Code Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill performs the advertised Google search task, but its installer can run newly downloaded third-party tooling with sudo/root privileges.
Install only if you are comfortable with a Google scraping helper that sends queries to Google and runs browser automation. Review the installer first, avoid running it on sensitive hosts, and do not allow the sudo step unless you have independently accepted the Scrapling dependency chain and host-level changes.
scripts/install.sh:21Unpinned Third-Party Dependencies Permit Supply-Chain Code Execution
scripts/install.sh:27Dynamically Installed Scrapling CLI Is Executed with Root Privileges
The skill performs networked Google searches but does not declare any explicit tool scope or permissions boundaries in the skill metadata. That omission weakens least-privilege controls and transparency for operators, making it easier for a seemingly simple skill to make outbound requests without clear policy review.
The skill documentation states that the installer may attempt to use sudo to install Playwright system dependencies, which exceeds the expected privilege level for a search helper. Invoking privileged system-level installation expands the blast radius from a local, isolated dependency setup to host-wide modification, increasing risk if the installer or its dependency chain is compromised.
The script sends the user's raw search query to Google through a live network request without any inline notice, confirmation step, or privacy warning. In this skill context, that matters because user queries may contain sensitive research topics, internal project names, credentials pasted by mistake, or other private data, and the use of a 'StealthyFetcher' makes the outbound transmission less transparent rather than more.
The install script goes beyond isolated virtualenv setup and invokes scrapling install, which can install browsers and system packages on the host. Because this action may run with elevated privileges and executes behavior from a freshly installed third-party package, it expands the trust boundary from local Python dependencies to host-level modification, creating meaningful supply-chain and privilege-risk exposure.
This line reflects logic that conditionally uses sudo, indicating the installer is prepared to escalate privileges during setup. Even if the echo line itself is not execution, in context it signals privileged host modification as part of installation, which is risky for an agent skill because users may run it expecting only local environment setup.
# Install browsers + system deps (may require sudo).
SCRAPLING_BIN="$VENV/bin/scrapling"
if [ -x "$SCRAPLING_BIN" ]; then
if command -v sudo >/dev/null 2>&1; then
echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
else
The use of sudo -E is a stronger form of privileged execution because it preserves environment variables when invoking the root process. In an installation script for a stealth-oriented scraping tool, this increases danger: environment injection or untrusted package behavior could influence a root-level install path and lead to broader host compromise or persistence.
SCRAPLING_BIN="$VENV/bin/scrapling"
if [ -x "$SCRAPLING_BIN" ]; then
if command -v sudo >/dev/null 2>&1; then
echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
else
echo "[stealthy-google-search] running: $SCRAPLING_BIN install"
The use of sudo -E is a stronger form of privileged execution because it preserves environment variables when invoking the root process. In an installation script for a stealth-oriented scraping tool, this increases danger: environment injection or untrusted package behavior could influence a root-level install path and lead to broader host compromise or persistence.
SCRAPLING_BIN="$VENV/bin/scrapling"
if [ -x "$SCRAPLING_BIN" ]; then
if command -v sudo >/dev/null 2>&1; then
echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
else
echo "[stealthy-google-search] running: $SCRAPLING_BIN install"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if [ -x "$SCRAPLING_BIN" ]; then
if command -v sudo >/dev/null 2>&1; then
echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
else
echo "[stealthy-google-search] running: $SCRAPLING_BIN install"
env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if [ -x "$SCRAPLING_BIN" ]; then
if command -v sudo >/dev/null 2>&1; then
echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
else
echo "[stealthy-google-search] running: $SCRAPLING_BIN install"
env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
The command-line arguments default to English (hl=en) and US locale (gl=us), which imposes a language/region preference even when the user does not request one. This is a natural-language policy concern because the skill forces a locale choice by default rather than asking the user or remaining neutral.