T08 · Insecure Dependencies
- Location
SKILL.md:38- Finding
Automatic Installation of Unpinned Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38-43
Vulnerability Type: Unpinned third-party package and runtime component installation
Risk Level: MediumComplete Code Snippet
bash if ! which browser-use &>/dev/null; then echo "INSTALLING browser-use..." uv tool install browser-use && browser-use install fi # 验证 which browser-use &>/dev/null && echo "READY" || echo "INSTALL_FAILED"Technical Analysis
The Skill instructs the agent to install
browser-useautomatically when it is unavailable. The command does not specify an exact package version, dependency lockfile, package hash, signature, or other integrity constraint. Consequently, the package and its transitive dependencies are resolved from mutable third-party supply-chain content at execution time.After installation, the newly obtained executable immediately runs
browser-use install, which may download and install additional browser components. Those artifacts are likewise not pinned or integrity-verified in the documented workflow. Because package installation and execution occur during ordinary Skill use, the effective code executed by the agent can differ from the code reviewed during this audit.This finding concerns unsafe dependency acquisition. The audited file does not establish that the current
browser-usepackage is malicious.Attack Path
- A user invokes the Twitter/X research Skill on a system where
browser-useis not installed. - The availability check fails.
- The agent executes
uv tool install browser-usewithout selecting an audited exact version or verifying artifact integrity. - A compromised package release, registry account, transitive dependency, package source, or distribution artifact supplies attacker-controlled code.
- The installed executable is immediately invoked through
browser-use install. - Attacker-controlled installation logic executes with the operating-sy ...[truncated 976 chars]
- A user invokes the Twitter/X research Skill on a system where
- Remediation
View remediation
Remediation Suggestions
- Remove automatic dependency installation from normal Skill execution and require explicit, informed user approval before installing software.
- Pin
browser-useto a reviewed exact version rather than resolving the latest available release. - Maintain and enforce a lockfile for all transitive dependencies.
- Verify downloaded package and browser-component hashes or trusted signatures before execution.
- Use an approved package index or internally mirrored artifact repository with provenance controls.
- Install dependencies during a separate, controlled provisioning stage rather than immediately before handling an authenticated browser session.
- Run browser automation in a sandboxed, least-privilege environment with restricted filesystem and network access.
- Use a dedicated browser profile containing only the minimum authentication state needed for the task.
- Document the expected component versions and periodically review them for known vulnerabilities before controlled upgrades.
