Back to skill

Security audit

Game Asset Generation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent CellCog game-asset helper with disclosed external dependency and API-key requirements, but users should install the dependency cautiously because the examples are not version-pinned.

Before installing, confirm you trust the CellCog publisher and prefer pinned or verified versions where your tooling supports it. Treat CELLCOG_API_KEY as a service credential, and review the base cellcog skill or SDK documentation before sending private project files or unreleased game assets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:255
Finding

Unpinned Third-Party Dependencies and Installation Commands

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13 and lines 255-258
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

The skill declares the CellCog dependency without a version constraint and recommends installation commands that retrieve mutable third-party packages without version pinning or integrity verification.

yaml
dependencies: [cellcog]
text
**Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog`
**OpenClaw:** `openclaw skills install @cellcog/cellcog`
**CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool)
**Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.

Technical Analysis

The dependency declaration does not identify an exact reviewed version. The documented npx, OpenClaw, and pip install -U commands can retrieve the latest package or skill content available from an external package registry or repository.

Because no version, immutable commit, integrity hash, lockfile, or signature-verification procedure is specified, the code installed by users can change after this skill has been reviewed. This creates a supply-chain exposure: compromise of the upstream package, registry namespace, repository, release process, or maintainer account could cause attacker-controlled code to be installed and executed.

The package and repository names are consistent with the declared CellCog service, so the available evidence does not establish intentional dependency confusion, typosquatting, or malicious behavior by the current publisher. The confirmed weakness is the absence of dependency pinning and integrity controls.

Attack Path

  1. An attacker compromises the upstream package registry account, repository, maintainer credentials, or release pipeline associated with a referenced dependency.
  2. The attacker pu ...[truncated 1505 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the Python dependency to an exact reviewed version, for example:
    text
    pip install cellcog==X.Y.Z
    
  2. Require package hashes where supported:
    text
    pip install --require-hashes -r requirements.txt
    
  3. Pin repository-based installations to an immutable, reviewed commit hash rather than a branch or mutable package tag.
  4. Replace implicit npx retrieval with an explicitly versioned package invocation or a separately verified installation step.
  5. Maintain a lockfile or dependency manifest recording exact versions and integrity digests.
  6. Verify package provenance through trusted publisher identities, signed releases, registry attestations, or equivalent supply-chain controls.
  7. Review installation scripts and package lifecycle hooks before allowing execution in an agent environment.
  8. Perform installation using a least-privileged account in an isolated virtual environment or container.
  9. Restrict access to CELLCOG_API_KEY until installation has completed and the installed package has been verified.
  10. Document the official registry and repository locations to reduce dependency-confusion and namespace-spoofing risks.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to run npx skills add cellcog/skills --skill cellcog without pinning an exact package version. This can cause users to fetch and execute whatever version is current at install time, increasing supply-chain risk if the package or a dependency is compromised or a breaking/malicious release is published.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.