T08 · Insecure Dependencies
- Location
SKILL.md:51- Finding
Unpinned Third-Party Packages and Browser Extension Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:51-58,SKILL.md:185-190
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumVulnerable Snippets
SKILL.md:51-54:bash npm install -g @jackwener/opencliSKILL.md:56-58additionally directs the user to download the latest Browser Bridge extension from the project's GitHub Releases page without identifying an immutable release or integrity value.SKILL.md:185-190:bash pip install yt-dlp # Alternative: brew install yt-dlpTechnical Analysis
The Skill directs users to install mutable, unpinned versions of OpenCLI, its browser extension, and
yt-dlp. It provides no package version constraints, immutable artifact URLs, cryptographic checksums, or signature-verification procedure.The global npm installation is particularly sensitive because npm installation and lifecycle scripts can execute with the invoking user's privileges. The browser extension is also security-sensitive because OpenCLI is documented as reusing authenticated Chrome sessions. Installing the unspecified “latest” release means the reviewed Skill does not uniquely determine the code that will eventually execute.
This is a supply-chain weakness rather than evidence that the named upstream projects are malicious. Exploitation would require compromise of an upstream package, maintainer account, registry, release process, download channel, or a future unsafe release.
Attack Path
- An attacker compromises an upstream maintainer account, package registry entry, GitHub release channel, or another component of the distribution process.
- The attacker publishes a malicious package or extension as the current version.
- A user follows the Skill and installs the dependency without a version pin or integrity check.
- Malicious package lifecycle code, executable code, or browser-extension logic runs locally.
- The payload accesses resource ...[truncated 749 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin OpenCLI and
yt-dlpto explicitly reviewed versions rather than installing the latest available release. - Provide immutable, official download URLs for the browser extension.
- Publish and verify SHA-256 checksums or trusted cryptographic signatures for downloaded artifacts.
- Avoid global npm installation where possible; use an isolated project environment, container, or restricted package runner.
- Consider disabling npm lifecycle scripts during initial package acquisition and explicitly reviewing required scripts before enabling them.
- Document the permissions requested by the browser extension and require users to verify them before installation.
- Establish a controlled dependency-update process that reviews release notes, source changes, signatures, and requested permissions before changing pinned versions.
- Pin OpenCLI and
