T08 · Insecure Dependencies
- Location
SKILL.md:195- Finding
Unpinned Global npm Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 195–199
Vulnerability Type: Unpinned third-party package installation from a mutable registry
Risk Level: MediumComplete Code Snippet:
bash npm install -g agent-browser agent-browser install # Download Chromium agent-browser install --with-deps # Linux: + system depsTechnical Analysis
The installation instructions globally install the latest available
agent-browsernpm package without pinning a reviewed version or verifying package integrity or provenance. Because registry package contents can change after this skill has been audited, the effective code installed by users is not fixed to the reviewed documentation.npm packages can execute lifecycle scripts during installation. A compromised package release or publishing account could therefore cause arbitrary code execution when a user follows the documented command. Global installation expands the affected environment beyond an isolated project. The subsequent
agent-browser installcommand downloads Chromium, while--with-depsmay install system dependencies and request elevated privileges, further increasing the supply-chain exposure and potential system impact.Attack Path
- An attacker compromises the npm package, its publisher account, or another relevant supply-chain component.
- The attacker publishes a malicious release under the expected package name.
- A user follows
SKILL.mdand runsnpm install -g agent-browserwithout an explicit version or integrity constraint. - npm resolves the mutable latest release and installs it globally.
- Malicious lifecycle scripts or subsequently invoked package code execute with the installing user's privileges.
- If the user then runs
agent-browser install --with-depswith elevated privileges, malicious package behavior may affect system-level files or dependency installation.
Impact As
...[truncated 539 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agent-browserto an explicitly reviewed version rather than installing the mutable latest release. - Verify npm package provenance, publisher identity, registry source, and integrity before installation.
- Prefer a project-local installation governed by a committed lockfile instead of a global installation.
- Use npm integrity and provenance controls and an approved internal registry or package allowlist where available.
- Disable lifecycle scripts during installation when they are unnecessary, then explicitly perform only reviewed setup actions.
- Run Chromium and operating-system dependency installation with least privilege and avoid granting administrative access to unverified package code.
- Document the exact trusted package version, expected integrity digest, registry URL, and required installation privileges.
- Periodically review pinned versions and update them only after security assessment.
- Pin
