T08 · Insecure Dependencies
- Location
SKILL.md:258- Finding
Unpinned Third-Party Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 258-262
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
markdown ## If CellCog is not installed **Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog` **OpenClaw:** `openclaw skills install @cellcog/cellcog` **CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool) **Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.Technical Analysis
The installation instructions retrieve mutable third-party content without pinning a package version, immutable commit, or integrity digest. The
pip install -U cellcogcommand explicitly requests an available upgrade, while thenpxand OpenClaw commands similarly identify remote packages without immutable versions.Consequently, the code installed when a user follows these instructions may differ from the content that was previously reviewed. If the package publisher, repository, distribution account, or upstream dependency is compromised, a malicious release could execute through package installation hooks or later SDK imports. The project provides no lockfile, hash verification, signature-verification procedure, or trusted-version constraint to mitigate that supply-chain risk.
This is a conditional supply-chain vulnerability; the audited file does not itself contain an embedded malicious payload.
Attack Path
- An attacker compromises an upstream package, repository, publisher account, or transitive dependency used by the documented installation commands.
- The attacker publishes a malicious release under the expected package identity.
- A user follows one of the unpinned installation instructions in
SKILL.md. - The package manager resolves and downloads the mutable malicious release.
- Malicious c ...[truncated 828 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CellCog package and skill to explicitly reviewed versions or immutable repository commit hashes.
- For Python installation, use an exact version constraint and verified hashes, for example through a locked requirements file with
--require-hashes. - For repository-based installation, reference an immutable commit rather than a mutable branch or default tag.
- Avoid
-Uin security-sensitive setup instructions because it can silently replace a reviewed dependency with a newer, unreviewed release. - Maintain and distribute dependency lockfiles that include transitive dependencies.
- Verify package publisher identity, release provenance, signatures, and integrity digests before installation.
- Perform installation in an isolated virtual environment or sandbox with minimal filesystem access and no unnecessary credentials.
- Review newly pinned releases before updating the documented version.
