T08 · Insecure Dependencies
- Location
SKILL.md:21- Finding
Unpinned Third-Party Dependency Installed with Access to Authenticated Browser Sessions
- Content
View full analysis
- Remediation
View remediation
" ``` 2. Maintain a lockfile containing exact transitive dependency versions. 3. Require package hashes where the package-management workflow supports them. 4. Explicitly identify and enforce the trusted package registry or index. 5. Document the versions and integrity controls applied by `browser-use install`. 6. Install and run the dependency in an isolated environment with only the permissions needed for mailbox summarization. 7. Avoid exposing an entire everyday browser profile where a dedicated, minimally privileged browser profile or provider API with read-only scopes can perform the task. 8. Review dependency updates before changing the pinned version and automate vulnerability scanning of the resolved dependency tree. ]]>
