T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party npm Package Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:31-41andreferences/commands.md:6-9
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
SKILL.md:31-41:markdown ### 1. Make sure the runtime is available Use `npx`, not a local repo path, unless the user explicitly wants development mode. Quick checks: ```bash npx browser-relay-cli version npx browser-relay-cli extension-pathtext The workflow subsequently starts the same unpinned package with: ```bash npx browser-relay-cli relay-startreferences/commands.md:6-9:bash npx browser-relay-cli version npx browser-relay-cli extension-path npx browser-relay-cli relay-start npx browser-relay-cli statusTechnical Analysis
The skill instructs the agent to execute
browser-relay-clithroughnpxwithout specifying an exact package version. No lockfile, package integrity hash, controlled package mirror, or documented provenance-verification step is provided.When the package is not already available locally,
npxcan retrieve the version currently resolved by the npm registry and execute its code with the privileges of the local user. Consequently, the effective executable may change after the skill has been reviewed. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream change could therefore introduce arbitrary behavior.The exposure is especially significant because the package starts a local browser relay and supplies an unpacked extension intended to operate within an already authenticated Chrome or Chromium session. Package code executes outside the browser sandbox as the current user, while the associated extension may interact with authenticated tabs and visible page content.
This finding does not establish that the current
browser-relay-clipackage is malicious. The risk arises from executing an unpinned, externally resolved dependency without reproducible dependency co ...[truncated 1602 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin every invocation to a specific reviewed release, for example:
bash npx --yes browser-relay-cli@X.Y.Z version npx --yes browser-relay-cli@X.Y.Z extension-path npx --yes browser-relay-cli@X.Y.Z relay-start npx --yes browser-relay-cli@X.Y.Z status -
Replace
X.Y.Zonly through a documented dependency-review process. Review package contents, dependency changes, lifecycle scripts, and extension permissions before approving an upgrade. -
Prefer a controlled installation with a committed lockfile and integrity metadata rather than resolving the package dynamically during each use.
-
Verify npm package provenance, publisher identity, release signatures or attestations where available, and registry integrity before execution.
-
Consider installing the approved package in a restricted environment and invoking that verified installation instead of allowing
npxto fetch code on demand. -
Run the relay under a dedicated least-privileged account or sandbox. Limit access to sensitive files, environment variables, local services, and unrelated browser profiles.
-
Inspect and verify the unpacked extension contents before loading them. Document the expected extension identifier, required permissions, and approved package checksum.
-
Apply the same exact-version requirement consistently in both
SKILL.mdandreferences/commands.mdso that the command catalog cannot reintroduce unpinned execution.
-
