T08 · Insecure Dependencies
- Location
SKILL.md:264- Finding
Unpinned Third-Party Package Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent CellCog data-analysis helper, but users should understand that selected datasets are uploaded to a third-party service for processing.
Install only if you are comfortable using CellCog as a third-party analysis service. Do not upload secrets, credentials, regulated records, or confidential business data unless your organization permits it, and prefer redacted or minimized datasets. Pin or verify dependencies where possible instead of relying on latest-version install commands.
SKILL.md:264Unpinned Third-Party Package Installation Creates a Supply-Chain Risk
SKILL.md:76Local Datasets May Be Disclosed to an External Analysis Service Without Adequate Privacy Safeguards
The metadata declares a required CELLCOG_API_KEY and implies remote service dependency, but the skill does not provide a clear privacy/security disclosure about external data transfer or handling. This omission can mislead users into exposing proprietary or personal data to a third-party service without informed consent. Because the skill explicitly supports uploads of CSV, Excel, JSON, Parquet, and SQL exports, the likelihood of sensitive-data submission is elevated.
The skill markets that CellCog 'runs the code for you' on uploaded files but does not clearly warn that user data is being sent to and processed by a remote service with full Python execution. Users may upload sensitive datasets believing analysis is local or low-risk, leading to unintended disclosure of confidential or regulated data. The context makes this more dangerous because the entire value proposition is automatic execution over arbitrary user-provided datasets.
The skill instructs users to install via npx skills add cellcog/skills --skill cellcog without pinning a specific version. This creates supply-chain risk because users may receive whatever package version is current at install time, including a compromised or breaking release. In a skill that already brokers code execution and remote data handling, unpinned installation increases exposure.
No suspicious patterns detected.