Back to skill

Security audit

Data Analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent CellCog data-analysis helper, but users should understand that selected datasets are uploaded to a third-party service for processing.

Install only if you are comfortable using CellCog as a third-party analysis service. Do not upload secrets, credentials, regulated records, or confidential business data unless your organization permits it, and prefer redacted or minimized datasets. Pin or verify dependencies where possible instead of relying on latest-version install commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:264
Finding

Unpinned Third-Party Package Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:76
Finding

Local Datasets May Be Disclosed to an External Analysis Service Without Adequate Privacy Safeguards

Content
View full analysis
"Analyze this dataset: > /path/to/customer_data.csv > > I don't know much about this data yet. Give me: > - Overview: rows, columns, data types, missing values > - Key distributions and summary statistics > - Most interesting correlations > - Any outliers or data quality issues > - 3-5 insights that jump out > > Present findings as an interactive HTML report with charts." ``` The same upload pattern is also recommended for business, customer, employee, survey, SQL-export, and other potentially sensitive datasets throughout `SKILL.md`. ### Technical Analysis The skill instructs agents to use `SHOW_FILE` with arbitrary local file paths and describes the service as analyzing uploaded files. This causes the selected dataset to be transferred to an external CellCog service for processing. Although external analysis is consistent with the documented purpose of the skill, the instructions do not require the agent to: - Obtain explicit and informed user approval before uploading each file. - Warn that file contents leave the local execution environment. - Detect or redact credentials, personal information, regulated records, or proprietary data. - Minimize uploaded columns and records. - Validate whether organizational policy permits the transfer. - Explain service retention, deletion, residency, access-control, or secondary-use policies. - Restrict file selection to an approved directory. The risk is therefore unintended disclosure caused by broad upload guidance without mandatory privacy controls. The reviewed file contains no evidence that the service maliciously collects data; the concern is the absence of safeguards around an intentional external transfer. ### Attack Path 1. A user asks the agent to analyze a local CSV, spreadsh ...[truncated 1364 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The metadata declares a required CELLCOG_API_KEY and implies remote service dependency, but the skill does not provide a clear privacy/security disclosure about external data transfer or handling. This omission can mislead users into exposing proprietary or personal data to a third-party service without informed consent. Because the skill explicitly supports uploads of CSV, Excel, JSON, Parquet, and SQL exports, the likelihood of sensitive-data submission is elevated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill markets that CellCog 'runs the code for you' on uploaded files but does not clearly warn that user data is being sent to and processed by a remote service with full Python execution. Users may upload sensitive datasets believing analysis is local or low-risk, leading to unintended disclosure of confidential or regulated data. The context makes this more dangerous because the entire value proposition is automatic execution over arbitrary user-provided datasets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to install via npx skills add cellcog/skills --skill cellcog without pinning a specific version. This creates supply-chain risk because users may receive whatever package version is current at install time, including a compromised or breaking release. In a skill that already brokers code execution and remote data handling, unpinned installation increases exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.