T08 · Insecure Dependencies
- Location
SKILL.md:278- Finding
Unpinned Third-Party Dependency and Mutable Installation Sources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:13andSKILL.md:278-281
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code:
yaml dependencies: [cellcog]markdown **Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog` **OpenClaw:** `openclaw skills install @cellcog/cellcog` **CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool) **Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.Technical Analysis
The Skill declares and recommends installing the third-party
cellcogcomponent without pinning an exact package version, immutable repository commit, or integrity hash. The manual command usespip install -U cellcog, which explicitly retrieves the newest package version available at installation time. Thenpxand OpenClaw installation instructions similarly identify mutable upstream content without an integrity constraint.Consequently, the code ultimately installed and executed may differ from the content that was reviewed. The external component contains the actual SDK, network, and execution behavior, but its implementation is absent from this project and could not be audited. This creates a supply-chain exposure if an upstream publisher account, package registry, repository, release process, or transitive dependency is compromised.
No evidence in the reviewed artifact establishes that the current upstream package is malicious. The vulnerability is the lack of reproducible, integrity-verified dependency resolution.
Attack Path
- An attacker compromises the relevant upstream package, repository, publisher account, or release channel.
- The attacker publishes a malicious release under the expected package or Skill identifier.
- A user follows one of the documented unpinned installation in ...[truncated 1093 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
cellcogto a specific, reviewed version rather than installing the latest release. - Where supported, pin repository-based installations to an immutable commit hash rather than a branch or mutable tag.
- Use lockfiles and require cryptographic package hashes, such as pip hash checking with a fully pinned requirements file.
- Document the expected package publisher, registry, and source repository so users can verify provenance.
- Verify package signatures or attestations and adopt provenance checks in the installation workflow where available.
- Audit and pin transitive dependencies, not only the top-level
cellcogpackage. - Avoid automatic upgrade instructions such as
pip install -Uin security-sensitive environments. Provide an explicit reviewed version and a controlled upgrade procedure instead. - Run the dependency with least privilege, restrict outbound network access to required endpoints, and provide a narrowly scoped and revocable
CELLCOG_API_KEY. - Vendor or include the runtime implementation in the review scope when feasible so its network, credential-handling, and code-execution behavior can be assessed.
- Pin
