T08 · Insecure Dependencies
- Location
SKILL.md:198- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:198-203
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumVulnerable Code
markdown ## If CellCog is not installed **Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog` **OpenClaw:** `openclaw skills install @cellcog/cellcog` **CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool) **Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.Technical Analysis
The installation instructions retrieve third-party components without specifying an exact version, immutable commit, or integrity hash. In particular,
pip install -U cellcogexplicitly installs the latest available package version, while thenpxand OpenClaw commands similarly identify mutable upstream packages or repositories.The reviewed project contains no lockfile, vendored dependency, checksum, or signature policy that would allow users to verify the installed artifacts against a known-good release. Although the audit found no evidence that the current CellCog packages are malicious, these instructions create a supply-chain exposure: the code ultimately installed and executed can change after this Skill has been reviewed.
Attack Path
- An attacker compromises an upstream package publisher account, source repository, package registry, or release process associated with one of the referenced dependencies.
- The attacker publishes a modified release containing malicious installation hooks or runtime behavior.
- A user follows one of the unpinned installation instructions in
SKILL.md. - The package manager resolves the mutable identifier to the compromised release.
- Installation or subsequent Skill execution runs the malicious code with the privileges of the invoking user or agent process.
This exploitation path depends on an ups ...[truncated 902 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every dependency to an exact, reviewed version rather than relying on mutable latest releases.
- For repository-based installation, reference an immutable commit hash or signed release tag.
- Publish and verify cryptographic hashes or signatures for downloaded artifacts where the package manager supports them.
- Remove the
-Uflag from the default Python installation command and document a tested version, for example:bash python3 -m pip install cellcog==<reviewed-version> - Maintain a lockfile or equivalent dependency manifest that records resolved versions and integrity metadata.
- Document the official package registry, publisher identity, source repository, and release-signing process so users can verify provenance.
- Recommend installation in an isolated virtual environment or sandbox using a non-privileged account.
- Establish a controlled upgrade process in which new versions are reviewed and tested before the pinned version is changed.
