T08 · Insecure Dependencies
- Location
SKILL.md:195- Finding
Unpinned Global Installation of a Third-Party Browser Automation Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 195-199
Vulnerability Type: Unpinned third-party dependency and mutable installation source
Risk Level: Mediumbash npm install -g agent-browser agent-browser install # Download Chromium agent-browser install --with-deps # Linux: + system depsTechnical Analysis
The installation instructions globally install
agent-browserwithout specifying a reviewed version or verifying package integrity. Consequently, the installed code depends on whichever package version the registry serves when the command is executed. The subsequent installation commands also download Chromium and, with--with-deps, may install system-level dependencies without documented artifact verification.If the package registry account, upstream release process, package contents, or downloaded browser artifacts are compromised, following these instructions could execute attacker-controlled installation or runtime code. A global installation increases exposure because the resulting executable is placed in the user's general command environment rather than being isolated to this project.
The audited files do not themselves contain a malicious payload. Exploitation depends on compromise or unsafe mutation of the external dependency or its distribution channel.
Attack Path
- An attacker compromises the package publisher, registry entry, release process, or an artifact downloaded by the installation command.
- The attacker publishes a malicious or modified release under the expected package identity.
- A user follows the Skill instructions and runs
npm install -g agent-browserwithout a pinned version or integrity check. - The package manager downloads and installs the attacker-controlled release globally.
- Package installation hooks or later CLI execution run malicious code with the privileges of the invoking user.
- If installation is performed with elevated privileges, ...[truncated 620 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto a specifically reviewed version rather than installing the latest available release:bash npm install --global agent-browser@<reviewed-version> - Record and verify the expected package integrity hash and obtain packages only from the documented official registry and publisher.
- Prefer a project-local installation with a lockfile over a global installation, then invoke the binary through the project package manager.
- Pin and verify downloaded Chromium artifacts, including their expected version and cryptographic checksum.
- Separate system-dependency installation from normal Skill use and require explicit administrator approval before running
install --with-deps. - Run the browser tool in a sandbox, container, or dedicated low-privilege account with restricted filesystem and credential access.
- Periodically review pinned releases and update them through a controlled dependency-review process rather than accepting automatic upstream changes.
- Pin
