T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Global Installation of Executable Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17–19
Vulnerability Type: Unpinned executable dependency obtained from a mutable package registry
Risk Level: MediumComplete Code Snippet:
bash npm install -g agent-browser agent-browser install agent-browser install --with-depsTechnical Analysis
The installation procedure retrieves
agent-browserfrom the npm registry without specifying an exact version or verifying an integrity hash. Consequently, the installed artifact can change after this Skill has been reviewed.npm installation may execute package lifecycle scripts, while the subsequent
agent-browser installcommands execute code supplied by the downloaded package. The--with-depsoption may additionally install or modify system-level dependencies. None of that executable dependency code is included in this project and therefore could not be inspected during this audit.Global installation increases exposure by placing the package in a shared environment rather than isolating it to this project. This is a supply-chain weakness; the audited files do not establish that the current upstream package is malicious.
Attack Path
- An attacker compromises the npm package maintainer account, package publication workflow, registry distribution path, or a transitive dependency.
- The attacker publishes a malicious package version under the default npm distribution tag.
- A user follows the documented
npm install -g agent-browsercommand. - npm retrieves the attacker-controlled release and may execute its lifecycle scripts with the invoking user's privileges.
- The user then runs
agent-browser installoragent-browser install --with-deps, providing another execution opportunity and potentially permitting broader system changes. - The malicious package can act within the permissions available to the invoking process.
Impact Assessment
Successful exploitati ...[truncated 563 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto an exact version that has been independently reviewed; do not use an omitted version or a mutable distribution tag. - Prefer a project-local dependency governed by a committed lockfile over global installation.
- Verify package provenance and integrity through npm integrity metadata, signed provenance where available, and a documented expected publisher and registry.
- Audit npm lifecycle scripts and the implementation of both installer commands before recommending execution.
- Run installation in a sandbox, container, or disposable least-privilege environment without production credentials.
- Avoid elevated privileges. If operating-system packages are necessary, enumerate and pin them explicitly rather than delegating unrestricted installation to a downloaded CLI.
- Establish an update-review process so a version change requires security review before documentation is updated.
- Pin
