Back to skill

Security audit

Dashboard

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent CellCog dashboard-building helper, with privacy and install-supply-chain cautions but no hidden or malicious behavior in the reviewed artifact.

Install only from the official CellCog source you trust, consider pinning or reviewing package versions before use, and avoid sending secrets, regulated personal data, or confidential business datasets to CellCog unless your organization has approved that processing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:198
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:198-203
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
## If CellCog is not installed

**Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog`
**OpenClaw:** `openclaw skills install @cellcog/cellcog`
**CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool)
**Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.

Technical Analysis

The installation instructions retrieve third-party components without specifying an exact version, immutable commit, or integrity hash. In particular, pip install -U cellcog explicitly installs the latest available package version, while the npx and OpenClaw commands similarly identify mutable upstream packages or repositories.

The reviewed project contains no lockfile, vendored dependency, checksum, or signature policy that would allow users to verify the installed artifacts against a known-good release. Although the audit found no evidence that the current CellCog packages are malicious, these instructions create a supply-chain exposure: the code ultimately installed and executed can change after this Skill has been reviewed.

Attack Path

  1. An attacker compromises an upstream package publisher account, source repository, package registry, or release process associated with one of the referenced dependencies.
  2. The attacker publishes a modified release containing malicious installation hooks or runtime behavior.
  3. A user follows one of the unpinned installation instructions in SKILL.md.
  4. The package manager resolves the mutable identifier to the compromised release.
  5. Installation or subsequent Skill execution runs the malicious code with the privileges of the invoking user or agent process.

This exploitation path depends on an ups ...[truncated 902 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every dependency to an exact, reviewed version rather than relying on mutable latest releases.
  2. For repository-based installation, reference an immutable commit hash or signed release tag.
  3. Publish and verify cryptographic hashes or signatures for downloaded artifacts where the package manager supports them.
  4. Remove the -U flag from the default Python installation command and document a tested version, for example:
    bash
    python3 -m pip install cellcog==<reviewed-version>
    
  5. Maintain a lockfile or equivalent dependency manifest that records resolved versions and integrity metadata.
  6. Document the official package registry, publisher identity, source repository, and release-signing process so users can verify provenance.
  7. Recommend installation in an isolated virtual environment or sandbox using a non-privileged account.
  8. Establish a controlled upgrade process in which new versions are reviewed and tested before the pinned version is changed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly encourages uploading CSV, JSON, and Excel files and building dashboards from user data, but it does not warn that this data may be sent to CellCog, an external service, for processing. This creates a privacy and data-governance risk because users may provide sensitive business, employee, survey, or log data without informed consent or awareness of third-party handling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to run npx skills add cellcog/skills --skill cellcog without pinning a specific package or version. This can cause users to fetch and execute whatever package version is current at install time, increasing supply-chain risk if the package is compromised or a malicious update is published.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.