Back to skill

Security audit

Playwright Stealth Verify

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed browser-fingerprint checking helper, with normal supply-chain and browser-session caution needed when running its npm tool.

Install only in a project or disposable environment you trust, pin and review the exact liarjs version where practical, use --offline or your own endpoint for sensitive tests, and do not attach it to a browser profile or CDP endpoint containing private sessions unless you intentionally want that session measured.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:38
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38-48
Vulnerability Type: Unsafe third-party dependency retrieval and execution
Risk Level: Medium

Complete Code Snippet:

markdown
Install as a dev dependency so the version is pinned in the lockfile:

```bash
npm install --save-dev liarjs

Against a browser started outside the test process

bash
npx liarjs@0.3 --cdp http://127.0.0.1:9222
text

### Technical Analysis

The documented workflow retrieves and executes the external npm package `liarjs`, but the project does not include the package source, a lockfile, an integrity hash, or other verification material.

The `npm install --save-dev liarjs` command does not specify a package version. It therefore resolves the version selected by the npm registry at installation time. The `npx liarjs@0.3` command is constrained to the `0.3` release line rather than an immutable, independently verified artifact and may download and immediately execute the resolved package.

This creates a supply-chain trust boundary that cannot be audited from the files in this project. If the registry package, publisher account, distribution channel, or a subsequently resolved release is compromised, package lifecycle scripts or the CLI entry point could execute attacker-controlled code with the invoking user's permissions. This finding does not establish that the current `liarjs` package is malicious; it identifies the unsafe and insufficiently reproducible dependency-execution pattern.

### Attack Path

1. An attacker compromises the external package publisher, registry entry, or another part of the npm distribution chain.
2. The attacker publishes malicious content under a version accepted by the documented command.
3. A user follows the Skill instructions and runs the unpinned `npm install` command or the `npx` command.
4. npm retrieves the externally controlled artifact.
5. Package lifecycle hook
...[truncated 786 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin a specific reviewed package version in every command, rather than using an unversioned package name or a version family such as 0.3.
  2. Commit a lockfile containing npm integrity hashes and require installation through npm ci.
  3. Review the exact package archive and its lifecycle scripts before recommending execution.
  4. Disable package lifecycle scripts with --ignore-scripts where the package can operate without them.
  5. Prefer a vendored, checksummed, or internally mirrored artifact from a controlled registry.
  6. Document the expected npm publisher, package checksum, registry, and verification procedure.
  7. Run the tool in a minimally privileged environment without unnecessary credentials or sensitive files.
  8. Restrict CDP endpoints to loopback or another trusted interface, require explicit user authorization before attachment, and use disposable browser profiles where practical.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.