T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 22
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: MediumVulnerable Code Snippet:
markdown 1. The host must have **Node ≥ 18** installed, and the service package must be installed globally: `npm install -g chrome-control-proxy`.Technical Analysis
The Skill directs users to install
chrome-control-proxyglobally from the configured npm registry without specifying an exact package version, verifying package integrity, providing a lockfile, or including the dependency's implementation in the audited project.Consequently, the code installed when this instruction is followed can differ from the code available when the Skill was reviewed. npm installation may also execute package lifecycle scripts, such as
preinstall,install, andpostinstall, with the privileges of the user running the command. The global installation scope places package executables in shared system or user-level npm locations, increasing the potential effect of a compromised release.The reviewed file does not establish that the package is malicious. The vulnerability is the unsafe supply-chain boundary created by retrieving and globally installing a mutable, unaudited dependency.
Attack Path
- An attacker compromises the npm publisher account, package repository, release pipeline, or another component of the package's distribution chain.
- The attacker publishes a malicious release under the legitimate
chrome-control-proxypackage name. - A user follows the Skill's unpinned command, causing npm to resolve and download the currently selected release.
- npm installs the package globally and may execute attacker-controlled lifecycle scripts.
- Malicious code runs with the invoking user's privileges or is later executed through the globally installed
ccpcommand. - Because the package controls a browser automation ...[truncated 874 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed exact version instead of resolving the latest compatible release:
bash npm install -g chrome-control-proxy@<audited-exact-version> - Document the expected package version and integrity digest, and verify the downloaded package archive before installation.
- Prefer a project-local installation with a committed lockfile over global installation:
bash npm install --save-exact chrome-control-proxy@<audited-exact-version> - Review the package source, transitive dependencies, published archive, and lifecycle scripts for the pinned release.
- Where compatible with the package's installation requirements, disable lifecycle scripts using
--ignore-scripts; otherwise, explicitly audit every required lifecycle script. - Use an approved registry, registry allowlisting, provenance verification, and continuous dependency monitoring.
- Run the service as a dedicated, unprivileged user and restrict its filesystem, network, browser-profile, and credential access.
- Bind the browser-control service only to a trusted local interface and require authentication or equivalent access controls if it can be reached across a network boundary.
- Pin the dependency to a reviewed exact version instead of resolving the latest compatible release:
