T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Global Installation of a Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20-22;CONTRIBUTING.md:25
Vulnerability Type: Unpinned and mutable third-party dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:20-22:bash npm install -g agent-browser agent-browser install agent-browser install --with-depsCONTRIBUTING.md:25:bash npm install -g agent-browser@latestTechnical Analysis
The documented installation process globally installs
agent-browserwithout pinning an exact reviewed version. The unversioned package specification resolves to the registry's current default release, while@latestexplicitly resolves through a mutable distribution tag.The project does not include a lockfile, package integrity hash, vendored implementation, or other mechanism that binds installation to the version reviewed during this audit. Because npm packages may contain lifecycle scripts and executable binaries, an altered or compromised future release could execute code under the privileges of the user performing the installation. A global installation also exposes the resulting executable across the user's environment rather than limiting it to this project.
No evidence was found that the current upstream package is malicious. The vulnerability is the unsafe, mutable dependency installation process.
Attack Path
- An attacker compromises the upstream npm package, its maintainer account, or the release pipeline.
- The attacker publishes a malicious release and assigns it to the registry's default or
latestdistribution tag. - A user follows the Skill instructions and runs the unpinned global installation command.
- npm downloads the attacker-controlled package and may execute its lifecycle scripts during installation.
- The malicious package runs with the installing user's privileges and installs or replaces the globally accessible
agent-browserexecutable. - Subsequent br ...[truncated 697 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto an exact version that has been reviewed, for example:bash npm install --save-exact agent-browser@<reviewed-version> - Prefer a project-local installation over a global installation, and invoke the dependency through an explicitly controlled project script or trusted package runner configuration.
- Commit a lockfile that records the complete dependency graph and integrity metadata.
- Document the expected npm registry and integrity hash for the reviewed package artifact.
- Remove the recommendation to install
@latest; version upgrades should require explicit review and testing. - Run installation with the least-privileged account available and do not use
sudoor an administrative shell. - Audit npm lifecycle scripts and transitive dependencies before approving each version update.
- Where practical, distribute a reproducibly built and cryptographically verified artifact.
- Pin
