Back to plugin

Security audit

CellCog

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real CellCog skills-only plugin, but it broadly routes work to an external agent and includes optional browser, SaaS, file-upload, and hosted-output workflows that need closer user review.

Review before installing if you handle confidential, regulated, personal, financial, legal, or proprietary data. Only send files you intend to upload to CellCog, avoid secrets and credentials, confirm consent for any real person's likeness or voice, and enable browser or connected SaaS tools only for a specific authorized task with the narrowest tools_selection possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is extremely broad ('any-to-any' across research, media, documents, dashboards, code, etc.), which can cause the skill to activate for a wide range of ordinary requests beyond a user's likely intent. Overbroad activation increases the chance that sensitive data, file paths, or privileged workflows are routed to an external service unnecessarily, especially given the skill's support for file upload, browser use, and connected tools.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill uses broad natural-language examples like creating a report or document without clear activation boundaries, which can cause the skill to be invoked for generic user requests unintentionally. In this skill’s context, accidental routing is risky because the resulting prompt and document content may be sent to an external CellCog service, potentially exposing sensitive business, legal, HR, or personal data.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The skill instructs users to set CELLCOG_API_KEY but provides no guidance on secure secret handling, such as avoiding hardcoding, not pasting keys into prompts, and using environment or secret managers. This increases the chance of accidental credential exposure through shell history, source control, logs, or agent transcripts.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill explicitly encourages users to upload pet photos, self-portraits, team photos, and mascot references, but it does not warn that these images may contain personal data, biometric identifiers, or third-party likenesses. This can lead users to share sensitive or non-consensual image data without understanding privacy, retention, or authorization implications.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly states that generated prototypes are hosted on live URLs, but it does not warn users that prompts, embedded sample data, or proprietary UI concepts may be sent to and exposed through an external hosted service. In a prototyping workflow, users may include internal product plans, customer-like data, or unreleased designs, so omission of this warning can lead to unintended disclosure to third parties or public link recipients.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill prominently markets data upload and analysis but does not clearly warn, up front, that uploaded files will be processed by a coding agent with full Python execution behind the scenes. That omission can cause users to submit sensitive or untrusted data without understanding the execution model and associated risks, increasing the chance of unsafe handling of confidential data or dangerous file parsing/code-execution side effects.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly promotes AI spokesperson and lipsync video generation but does not warn about consent, likeness rights, impersonation, or deceptive media risks. This omission can normalize or facilitate creation of non-consensual or misleading synthetic media, especially because the examples encourage realistic presenter-style outputs that could be applied to real people or authority figures.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The examples encourage enabling real-browser control and connected SaaS tools at task creation time, but the warning nearby focuses on availability/credits rather than explicit privacy, consent, and scope risks. In this skill's context, those capabilities can expose authenticated sessions, mailbox contents, dashboards, and other private account data to an external agent, making accidental over-sharing or unauthorized actions more likely.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly promotes cloned-voice and avatar voice generation without any warning about consent, impersonation, or abuse risks. In this context, the omission makes it easier for users to misuse the feature for deceptive impersonation, fraud, or non-consensual voice cloning, especially because the examples normalize personalized voice generation as a routine workflow.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly encourages image editing and reference-based generation using user-supplied images through an external CellCog service, but it does not disclose that uploaded images may leave the local environment and be processed by a third party. This can lead to unintended disclosure of sensitive photos, personal data, or proprietary brand assets, especially because users may assume a local capability when interacting with an agent skill.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill explicitly states that CellCog deploys generated diagrams as interactive web applications with shareable URLs, but it does not present a clear user-facing warning near usage guidance that sensitive architectural, network, database, or organizational details may be exposed outside the local environment. Because the skill encourages users to submit internal system descriptions and infrastructure layouts, the lack of a prominent disclosure can lead to unintentional external sharing of confidential information.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill markets spreadsheet generation for financial, budget, employee, sales, and other potentially sensitive datasets, but it does not disclose that user prompts and spreadsheet contents may be transmitted to an external CellCog service. This creates a meaningful privacy and data-governance risk because users may paste personal, financial, or business-confidential data without informed consent or proper handling expectations.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs users to send arbitrary research prompts to the external CellCog service and to configure a CellCog API key, but it does not clearly disclose that prompt contents and attached context may be transmitted to a third-party provider. In an agent environment, users may include sensitive business data, credentials, internal documents, or regulated information in research prompts, creating confidentiality, compliance, and data-governance risk if they are sent off-platform without explicit warning or consent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill encourages users to submit resumes, contracts, invoices, NDAs, legal documents, and reports, but does not warn that prompts and document contents are transmitted to an external CellCog service. Because these document types often contain sensitive personal, financial, legal, and proprietary information, users may unknowingly disclose confidential data to a third party.

VirusTotal

65/65 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.