T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Third-Party Browser Automation Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20-30
Vulnerability Type: Unpinned executable dependency and supply-chain exposure
Risk Level: MediumVulnerable Code:
bash npm install -g agent-browser # Or install it at project level npm install agent-browserbash npx agent-browser --versionTechnical Analysis
The Skill instructs users to install and execute
agent-browserwithout pinning an exact reviewed version, supplying a lockfile, or verifying package integrity. Consequently, the installed implementation may change independently of the audited Skill.Both global and project-level npm installation execute package-controlled installation logic with the permissions of the invoking user. Subsequent
npx agent-browsercommands execute the installed package. Depending on npm andnpxconfiguration,npxmay also retrieve a missing package from the configured registry.The browser automation capability is relevant to the declared extraction function, but retrieving an unpinned executable package is broader and less deterministic than necessary. The inspected project does not establish that the resolved package version is the same version reviewed by the Skill author.
Attack Path
- An attacker compromises the upstream package, a maintainer account, or the package distribution channel.
- A malicious or otherwise unsafe version is published under the expected package name.
- A user follows the Skill instructions and runs
npm install -g agent-browser,npm install agent-browser, or annpx agent-browserinvocation without a verified local installation. - npm retrieves the affected release.
- Package lifecycle scripts or the package CLI execute with the user's local permissions.
- The malicious package can access resources available to that user, independently of the fixed DOM extraction code shown in the Skill.
Impact Assessment
Successful exp ...[truncated 625 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto an exact, reviewed version rather than relying on the registry's current version. - Add a package manifest and committed lockfile containing integrity metadata.
- Install dependencies using a deterministic command such as
npm ci. - Invoke only the verified local installation, for example with
npx --no-install agent-browser, to prevent implicit downloads. - Review package lifecycle scripts and disable unnecessary scripts during installation where operationally possible.
- Document the reviewed package source, exact version, expected integrity hash, and update process.
- Run browser automation under a restricted, non-administrative account with access limited to the files required for extraction.
- Pin
