T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party Package and Browser Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–25
Vulnerability Type: Unpinned dependency installation without integrity verification
Risk Level: MediumVulnerable code:
bash npm install -g @playwright/test # Or pip install playwrightbash playwright install # Install only specific browsers playwright install chromium firefox # Install system dependencies on Linux playwright install-depsTechnical Analysis
The installation instructions retrieve the latest available versions of the Playwright package, browser binaries, and potentially operating-system dependencies at execution time. No exact package version, lockfile, package hash, browser revision validation, or trusted artifact policy is specified.
Consequently, the code reviewed during the audit may differ from the code installed later. A compromised package registry account, malicious future release, registry or repository compromise, or dependency-chain compromise could cause attacker-controlled installation scripts or binaries to execute. The global npm installation also broadens the affected environment, while
playwright install-depscan modify system packages and may request elevated privileges depending on the host configuration.The audit did not identify evidence that the currently named official Playwright packages are malicious. The finding concerns the unsafe, non-reproducible dependency acquisition process.
Attack Path
- An attacker compromises an upstream package, maintainer account, transitive dependency, browser artifact distribution channel, or relevant package repository.
- The compromised component is published under a version accepted by the unpinned installation commands.
- A user or agent follows
SKILL.mdand runsnpm install -g @playwright/test,pip install playwright, or the Playwright browser and system-dependency installation commands. - The package manager download ...[truncated 848 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin npm and Python dependencies to explicitly reviewed versions, for example
@playwright/test@<approved-version>andplaywright==<approved-version>. - Prefer a project-local npm installation with a committed lockfile and
npm ciinstead of a global installation. - For Python, use a locked requirements file that includes cryptographic hashes and install with
pip install --require-hashes -r requirements.txt. - Pin the Playwright package and associated browser revisions together; do not independently update browser artifacts without review.
- Download dependencies only from approved registries and repositories, and apply package-manager provenance or signature verification where available.
- Perform installation in an isolated, non-privileged environment such as a container or dedicated virtual environment.
- Avoid automatic execution of
playwright install-deps. Document the required operating-system packages and versions, review them separately, and require explicit approval before privileged installation. - Scan and test dependency updates before promoting them into the trusted execution environment.
- Pin npm and Python dependencies to explicitly reviewed versions, for example
