T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Global Installation of a Third-Party Browser Automation Package
- Content
View full analysis
- Remediation
View remediation
``` 2. Maintain and verify a lockfile and npm integrity metadata. 3. Document the expected package publisher and official registry source. 4. Prefer a project-local installation or an isolated execution environment over a global installation. 5. Disable npm lifecycle scripts during installation where compatible: ```bash npm install --ignore-scripts --save-exact agent-browser@ ``` 6. Review the package and required lifecycle scripts before enabling any installation scripts. 7. Run the dependency with a dedicated, least-privileged account or inside a disposable container. 8. Establish an upgrade process that reviews changelogs, package provenance, and dependency changes before changing the pinned version. ]]>
