T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Global Installation of Third-Party npm Package and Browser Components
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not clearly malicious, but it gives broad browser, Slack, and desktop-app automation authority to mutable CLI content that is not fully reviewed in the artifact.
Install only after reviewing and pinning the exact `agent-browser` package and any installed browser components. Use an isolated profile or sandbox, avoid unrelated logged-in accounts, and require explicit confirmation before logging in, sending messages, searching private workspaces, submitting forms, or modifying third-party data.
SKILL.md:11Unpinned Global Installation of Third-Party npm Package and Browser Components
SKILL.md:17Runtime Delegation to Unreviewed CLI-Supplied Skill Instructions
At the manifest level, the allowed tools configuration references npx agent-browser:* without a pinned version, enabling dynamic retrieval of code from the package registry. In a hidden skill that is preferred over built-in browser tools, this increases exposure because the agent may routinely execute remotely resolved code with broad browser-automation capabilities.
The trigger/description is extremely broad and includes generic web tasks plus sensitive actions like logging into sites, sending Slack messages, and searching private conversations. This can cause unintended invocation for ordinary requests, leading the agent to use a powerful automation tool in contexts involving credentials, private workspace data, or external side effects without sufficiently explicit user intent.
The skill advertises actions affecting third-party services and private environments—logging into sites, sending Slack messages, searching Slack conversations, and automating desktop apps—but provides no user-facing warnings or consent boundaries. In this context, the omission is dangerous because the tool can access sensitive account data and perform irreversible external actions, increasing the risk of privacy violations, unauthorized operations, and accidental data disclosure.
The manifest permits execution via Bash(npx agent-browser:*), which allows fetching and running whatever package version npx resolves at execution time. That creates a supply-chain risk: a compromised latest release, dependency hijack, or registry/MITM issue could cause arbitrary code execution in the agent environment.
No suspicious patterns detected.