T08 · Insecure Dependencies
- Location
SKILL.md:198- Finding
Unpinned Global Dependency Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 198-200
Vulnerability Type: Unpinned third-party package installation
Risk Level: Mediumbash npm install -g agent-browser agent-browser install # Download Chromium agent-browser install --with-deps # Linux: + system depsTechnical Analysis
The installation instructions retrieve the
agent-browsernpm package without specifying an exact version or integrity value. Consequently, the installed code depends on whichever package release the registry resolves at installation time rather than a release that was reviewed with this Skill.The package is installed globally and its executable is subsequently invoked to download Chromium or install additional system dependencies. npm package lifecycle scripts and the invoked installer can execute code with the permissions of the user running these commands. If the package, maintainer account, registry publication process, or a transitive dependency is compromised, the downloaded code could differ materially from the code reviewed when the Skill was published.
The repository reference in the documentation does not cryptographically bind the npm installation to a specific reviewed source revision. The project contains no lockfile, package integrity hash, provenance verification procedure, or version constraint that mitigates this mutable-dependency risk.
Attack Path
- An attacker compromises the npm package, a maintainer account, or a dependency included by a future package release.
- The attacker publishes a malicious or backdoored version under the expected package name.
- A user follows the documented
npm install -g agent-browsercommand. - npm resolves and installs the attacker-controlled version because no exact version or integrity constraint is present.
- Malicious package lifecycle code may execute during installation, or the payload may execute when the ...[truncated 1022 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto a reviewed exact version rather than relying on the registry's current release. - Verify npm provenance, package signatures where available, and published integrity information before installation.
- Document the expected package version, source revision, Chromium artifact, checksums, and publisher identity.
- Prefer a project-local installation with a committed lockfile over global installation, reducing system-wide exposure and ensuring deterministic dependency resolution.
- Disable npm lifecycle scripts during initial package retrieval where operationally possible, then review any required scripts before explicitly running them.
- Perform installation and browser downloads in a sandbox, container, or otherwise restricted account.
- Do not run
--with-depswith elevated privileges until the exact installer version and its system-level actions have been reviewed. - Periodically review and deliberately update the pinned version instead of accepting automatic mutable updates.
- Pin
