T08 · Insecure Dependencies
- Location
SKILL.md:137- Finding
Unpinned Global Installation of a Third-Party Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 137–140
Vulnerability Type: Supply-chain exposure through a mutable dependency version and global installation
Risk Level: MediumVulnerable code:
bash # If `npx` is missing, install Node/npm and then install Playwright globally: npm install -g @playwright/mcp@latestTechnical Analysis
The Skill instructs the agent to install
@playwright/mcpglobally using the mutablelatesttag. The package version resolved at execution time can therefore differ from the version assessed when the Skill was audited.The instruction provides no exact version pin, lockfile, integrity verification, or package-content validation. In addition, npm package installation can invoke package lifecycle scripts with the privileges of the user running npm. The global
-gscope also affects the user's wider Node.js environment rather than an isolated project dependency tree.This is a supply-chain weakness rather than evidence that the currently published package is malicious. Exploitation requires compromise or unexpected modification of the package release, its publishing account, or the configured npm registry.
Attack Path
- Playwright or
npxis unavailable in the environment. - The agent follows the prerequisite instructions and installs Node.js/npm.
- The agent executes
npm install -g @playwright/mcp@latest. - npm resolves
latestfrom the configured registry at installation time. - If the resolved package or one of its dependencies has been compromised, malicious package content or lifecycle scripts execute under the invoking user's account.
- Because installation is global, malicious or incompatible files may affect commands and packages outside the audited project.
Impact Assessment
A compromised dependency could execute code with the privileges of the user invoking npm. Depending on that user's permissions and environment, thi ...[truncated 454 chars]
- Playwright or
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version. - Prefer a project-local development dependency rather than a global installation.
- Commit a lockfile and install with
npm cito enforce the reviewed dependency graph. - Verify package provenance and registry configuration before installation.
- Preserve and validate npm integrity metadata.
- Disable lifecycle scripts when they are unnecessary, for example with
--ignore-scripts, after confirming that doing so does not break the dependency. - Run installation as a non-privileged user in an isolated workspace or container.
- Document the expected package version and a controlled upgrade-review process.
A safer pattern would be:
bash npm install --save-dev --save-exact @playwright/mcp@<reviewed-version> npm ci- Replace
