T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned Global Playwright Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 28-29
Vulnerability Type: Unpinned, globally installed third-party dependency
Risk Level: MediumVulnerable code:
bash npm install -g playwright playwright install chromiumTechnical Analysis
The installation instructions retrieve the latest available Playwright package from the configured npm registry without specifying a reviewed version or providing a lockfile. The package is also installed globally, increasing its potential effect on the user environment and allowing the same mutable installation to be shared by unrelated projects.
npm installation may execute package lifecycle scripts. Consequently, compromise of the package, one of its transitive dependencies, the registry account, or the registry configuration could result in attacker-controlled code executing with the privileges of the user performing the installation. The subsequent browser installation also downloads executable browser components without project-level version controls documented by this Skill.
This finding does not establish that the current Playwright package is malicious. The vulnerability is the unsafe dependency acquisition and installation practice.
Attack Path
- An attacker compromises a relevant npm package release, maintainer account, transitive dependency, or registry used by the operator.
- The operator follows the Skill documentation and runs
npm install -g playwrightwithout a pinned version. - npm resolves and downloads the attacker-controlled mutable release.
- Malicious package contents or lifecycle scripts execute during installation under the operator's account.
- The attacker may access data available to that account, alter globally installed tooling, or place additional malicious files within writable locations.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user running ...[truncated 507 chars]
- Remediation
View remediation
Remediation Suggestions
- Create a project-local
package.jsonand pin Playwright to a specifically reviewed version. - Commit a generated lockfile and use
npm ciso installations follow the locked dependency graph. - Avoid global package installation; invoke the project-local dependency from the Skill.
- Configure npm to use a trusted registry and retain package-integrity verification.
- Review dependency updates before changing the pinned version, and use automated dependency and vulnerability scanning.
- Document a reproducible browser installation process tied to the pinned Playwright release.
- Avoid running package installation with administrative privileges.
- Create a project-local
