Back to skill

Security audit

Comic Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward CellCog comic-generation guide, with a real but disclosed supply-chain caution around installing the unpinned CellCog dependency.

Install this only if you trust CellCog as the provider and are comfortable configuring a CELLCOG_API_KEY. For stricter environments, pin the CellCog package or skill to a reviewed version and use a limited, revocable API key.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:278
Finding

Unpinned Third-Party Dependency and Mutable Installation Sources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13 and SKILL.md:278-281
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

yaml
dependencies: [cellcog]
markdown
**Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog`
**OpenClaw:** `openclaw skills install @cellcog/cellcog`
**CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool)
**Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.

Technical Analysis

The Skill declares and recommends installing the third-party cellcog component without pinning an exact package version, immutable repository commit, or integrity hash. The manual command uses pip install -U cellcog, which explicitly retrieves the newest package version available at installation time. The npx and OpenClaw installation instructions similarly identify mutable upstream content without an integrity constraint.

Consequently, the code ultimately installed and executed may differ from the content that was reviewed. The external component contains the actual SDK, network, and execution behavior, but its implementation is absent from this project and could not be audited. This creates a supply-chain exposure if an upstream publisher account, package registry, repository, release process, or transitive dependency is compromised.

No evidence in the reviewed artifact establishes that the current upstream package is malicious. The vulnerability is the lack of reproducible, integrity-verified dependency resolution.

Attack Path

  1. An attacker compromises the relevant upstream package, repository, publisher account, or release channel.
  2. The attacker publishes a malicious release under the expected package or Skill identifier.
  3. A user follows one of the documented unpinned installation in ...[truncated 1093 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin cellcog to a specific, reviewed version rather than installing the latest release.
  2. Where supported, pin repository-based installations to an immutable commit hash rather than a branch or mutable tag.
  3. Use lockfiles and require cryptographic package hashes, such as pip hash checking with a fully pinned requirements file.
  4. Document the expected package publisher, registry, and source repository so users can verify provenance.
  5. Verify package signatures or attestations and adopt provenance checks in the installation workflow where available.
  6. Audit and pin transitive dependencies, not only the top-level cellcog package.
  7. Avoid automatic upgrade instructions such as pip install -U in security-sensitive environments. Provide an explicit reviewed version and a controlled upgrade procedure instead.
  8. Run the dependency with least privilege, restrict outbound network access to required endpoints, and provide a narrowly scoped and revocable CELLCOG_API_KEY.
  9. Vendor or include the runtime implementation in the review scope when feasible so its network, credential-handling, and code-execution behavior can be assessed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx skills add cellcog/skills --skill cellcog without pinning a specific package or version, which creates a supply-chain risk. npx may fetch the latest package at execution time, so a compromised publisher account, malicious update, or dependency hijack could cause unreviewed code to run on the user's machine.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.