Back to skill

Security audit

Logo Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward CellCog branding helper, with the main caution being mutable third-party install commands for CellCog setup.

Before installing, verify that the CellCog package and skill source are the ones you intend to trust, consider pinning versions in your own environment, and use a scoped CELLCOG_API_KEY because prompts and branding inputs will be handled by CellCog.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:258
Finding

Unpinned Third-Party Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 258-262
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

markdown
## If CellCog is not installed

**Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog`
**OpenClaw:** `openclaw skills install @cellcog/cellcog`
**CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool)
**Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.

Technical Analysis

The installation instructions retrieve mutable third-party content without pinning a package version, immutable commit, or integrity digest. The pip install -U cellcog command explicitly requests an available upgrade, while the npx and OpenClaw commands similarly identify remote packages without immutable versions.

Consequently, the code installed when a user follows these instructions may differ from the content that was previously reviewed. If the package publisher, repository, distribution account, or upstream dependency is compromised, a malicious release could execute through package installation hooks or later SDK imports. The project provides no lockfile, hash verification, signature-verification procedure, or trusted-version constraint to mitigate that supply-chain risk.

This is a conditional supply-chain vulnerability; the audited file does not itself contain an embedded malicious payload.

Attack Path

  1. An attacker compromises an upstream package, repository, publisher account, or transitive dependency used by the documented installation commands.
  2. The attacker publishes a malicious release under the expected package identity.
  3. A user follows one of the unpinned installation instructions in SKILL.md.
  4. The package manager resolves and downloads the mutable malicious release.
  5. Malicious c ...[truncated 828 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CellCog package and skill to explicitly reviewed versions or immutable repository commit hashes.
  2. For Python installation, use an exact version constraint and verified hashes, for example through a locked requirements file with --require-hashes.
  3. For repository-based installation, reference an immutable commit rather than a mutable branch or default tag.
  4. Avoid -U in security-sensitive setup instructions because it can silently replace a reviewed dependency with a newer, unreviewed release.
  5. Maintain and distribute dependency lockfiles that include transitive dependencies.
  6. Verify package publisher identity, release provenance, signatures, and integrity digests before installation.
  7. Perform installation in an isolated virtual environment or sandbox with minimal filesystem access and no unnecessary credentials.
  8. Review newly pinned releases before updating the documented version.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx skills add cellcog/skills --skill cellcog without pinning an exact package or repository version. This can expose users to supply-chain risk if the referenced package, dependency chain, or fetched remote content changes maliciously or unexpectedly over time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.