T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Global Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–48
Vulnerability Type: Unpinned and globally installed dependencies
Risk Level: Mediumbash # Install Playwright npm install -g playwright # Install browsers (Chrome, Firefox, Safari) npx playwright install # Install Chrome extension for stealth (optional) npm install -g playwright-extra playwright-extra-plugin-stealthTechnical Analysis
The installation instructions retrieve the latest available versions of multiple npm packages without a version constraint or lockfile. The packages are installed globally, expanding their influence beyond an isolated project environment. The
npx playwright installcommand also downloads browser binaries based on the installed Playwright package.Package installation can execute npm lifecycle scripts. Consequently, a compromised package release, transitive dependency, npm registry response, or future malicious version could execute code with the privileges of the user following these instructions. The optional stealth packages increase the supply-chain surface and are not required for the core browser-automation functionality.
Attack Path
- An attacker compromises a listed npm package, one of its transitive dependencies, or the package distribution channel.
- A user follows the Skill instructions and runs an unpinned global installation command.
- npm resolves the compromised release because no reviewed version or lockfile is enforced.
- Malicious package code or an installation lifecycle script executes under the installing user's account.
- The payload may access user-readable files, environment variables, browser data, and credentials, or modify globally installed tooling.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user performing the installation. The accessible scope may include user files, environment secrets ...[truncated 221 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace global installations with project-local dependencies.
- Pin every dependency to a reviewed exact version.
- Commit a lockfile and use
npm cito enforce reproducible dependency resolution. - Review package provenance, maintainers, integrity metadata, and lifecycle scripts before installation.
- Use a trusted npm registry and retain registry integrity verification.
- Remove
playwright-extraandplaywright-extra-plugin-stealthfrom the standard procedure unless a documented use case explicitly requires them. - Execute dependency installation in a non-privileged, isolated environment without access to production credentials.
