T08 · Insecure Dependencies
- Location
SKILL.md:255- Finding
Unpinned Third-Party Dependencies and Installation Commands
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 13 and lines 255-258
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumThe skill declares the CellCog dependency without a version constraint and recommends installation commands that retrieve mutable third-party packages without version pinning or integrity verification.
yaml dependencies: [cellcog]text **Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog` **OpenClaw:** `openclaw skills install @cellcog/cellcog` **CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool) **Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.Technical Analysis
The dependency declaration does not identify an exact reviewed version. The documented
npx, OpenClaw, andpip install -Ucommands can retrieve the latest package or skill content available from an external package registry or repository.Because no version, immutable commit, integrity hash, lockfile, or signature-verification procedure is specified, the code installed by users can change after this skill has been reviewed. This creates a supply-chain exposure: compromise of the upstream package, registry namespace, repository, release process, or maintainer account could cause attacker-controlled code to be installed and executed.
The package and repository names are consistent with the declared CellCog service, so the available evidence does not establish intentional dependency confusion, typosquatting, or malicious behavior by the current publisher. The confirmed weakness is the absence of dependency pinning and integrity controls.
Attack Path
- An attacker compromises the upstream package registry account, repository, maintainer credentials, or release pipeline associated with a referenced dependency.
- The attacker pu ...[truncated 1505 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the Python dependency to an exact reviewed version, for example:
text pip install cellcog==X.Y.Z - Require package hashes where supported:
text pip install --require-hashes -r requirements.txt - Pin repository-based installations to an immutable, reviewed commit hash rather than a branch or mutable package tag.
- Replace implicit
npxretrieval with an explicitly versioned package invocation or a separately verified installation step. - Maintain a lockfile or dependency manifest recording exact versions and integrity digests.
- Verify package provenance through trusted publisher identities, signed releases, registry attestations, or equivalent supply-chain controls.
- Review installation scripts and package lifecycle hooks before allowing execution in an agent environment.
- Perform installation using a least-privileged account in an isolated virtual environment or container.
- Restrict access to
CELLCOG_API_KEYuntil installation has completed and the installed package has been verified. - Document the official registry and repository locations to reduce dependency-confusion and namespace-spoofing risks.
- Pin the Python dependency to an exact reviewed version, for example:
