T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned Third-Party Installation Creates a Supply-Chain Execution Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:19-32;CONTRIBUTING.md:23-26
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumVulnerable Code
SKILL.md:19-32:bash npm install -g agent-browser agent-browser install agent-browser install --with-depsbash git clone https://github.com/vercel-labs/agent-browser cd agent-browser pnpm install pnpm build agent-browser installCONTRIBUTING.md:23-26:bash npm install -g agent-browser@latestTechnical Analysis
The installation instructions execute mutable third-party content without pinning an audited package version, commit hash, lockfile state, or integrity digest. The
@latestspecifier explicitly selects whichever release is current when installation occurs. Similarly, cloning the repository without checking out a fixed commit executes the current default branch throughpnpm install, lifecycle scripts, and the build process.Package-manager lifecycle hooks and transitive dependencies can execute arbitrary code during installation. The subsequent
agent-browser install --with-depsoperation may also install browser and operating-system dependencies. While the documented npm package and GitHub repository appear consistent with the stated upstream project, the instructions provide no protection against a future compromised release, maintainer account, repository branch, or transitive dependency.Attack Path
- An attacker compromises the upstream package, maintainer credentials, repository branch, or a transitive dependency.
- The attacker publishes a malicious release under the existing package name or inserts malicious installation/build logic into the mutable repository state.
- A user follows the documented
npm install -g agent-browser,@latest, or unpinned source-build instructions. - npm or pnpm downloads the attacker-controlled content.
- Instal ...[truncated 918 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto a specific reviewed version rather than using an implicit current release or@latest. - For source installation, check out a specific reviewed commit hash or signed release tag before installing dependencies or building.
- Supply and enforce a lockfile for transitive dependencies.
- Document package-signature, provenance, checksum, or integrity verification where supported.
- Avoid global installation where possible; prefer a project-local, isolated environment.
- Explain whether
--with-depsrequires elevated privileges and recommend running unprivileged steps separately from narrowly scoped privileged operations. - Review dependency changes before updating the pinned package version or source commit.
- Pin
