T08 · Insecure Dependencies
- Location
SKILL.md:197- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 197-200
Vulnerability Type: Unpinned third-party dependency and unsafe global installation
Risk Level: Mediumbash npm install -g agent-browser agent-browser install # Download Chromium agent-browser install --with-deps # Linux: + system depsTechnical Analysis
The installation instructions globally install
agent-browserwithout specifying an exact package version or verifying an integrity digest. Consequently, npm resolves the package release available at installation time rather than a release that was reviewed with this skill.npm installation can execute package lifecycle scripts. After installation, the documented CLI commands also download Chromium and may install operating-system dependencies. Those remotely obtained components and their installation behavior are not present in the audited artifact and therefore cannot be verified by this static review.
The combination of an unpinned dependency, global installation, lifecycle-script execution, and subsequent component downloads creates a software supply-chain exposure. Exploitation would require compromise or malicious control of the npm package, its publication channel, or another relevant distribution endpoint.
Attack Path
- An attacker compromises the
agent-browserpackage publication channel, maintainer credentials, or an associated component distribution endpoint. - The attacker publishes a malicious or modified release under the package name or replaces a downloaded installation artifact.
- A user follows the skill documentation and runs
npm install -g agent-browser. - npm resolves the attacker-controlled current release because no exact version or integrity value is specified.
- Malicious lifecycle scripts or installed package code execute with the privileges of the user running npm.
- The user subsequently runs `agent-browser inst ...[truncated 834 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto an exact, reviewed version instead of installing the latest available release. - Use a project-local dependency with a committed lockfile rather than a global installation where feasible.
- Verify package integrity through a trusted registry, recorded cryptographic digest, provenance attestations, and package signatures where supported.
- Audit npm lifecycle scripts before installation and disable them with
--ignore-scriptswhen they are not required. - Pin and verify Chromium downloads and other external installation artifacts using documented versions and checksums.
- Separate browser installation from operating-system dependency installation, and clearly document when elevated privileges may be requested.
- Run installation in a least-privileged, isolated environment and avoid using an administrator or root account.
- Document the expected official package publisher and distribution endpoints so users can detect package substitution or registry misconfiguration.
- Pin
