Back to skill

Security audit

Stock Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real financial-analysis integration, but it combines sensitive financial guidance with mutable third-party install instructions and limited user warnings.

Install only if you trust CellCog and are comfortable sending financial prompts, portfolio details, and related context to that service. Prefer a pinned, verified package or skill version, use a restricted/rotatable `CELLCOG_API_KEY`, avoid sharing unnecessary sensitive records, and treat outputs as informational rather than professional financial, tax, legal, or investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:218
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13 and 218–221
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

yaml
dependencies: [cellcog]
markdown
## If CellCog is not installed

**Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog`
**OpenClaw:** `openclaw skills install @cellcog/cellcog`
**CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool)
**Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.

Technical Analysis

The skill declares and recommends installing the cellcog dependency without an exact version, cryptographic hash, verified signature, or lockfile. The pip install -U cellcog command explicitly selects the latest package version available at installation time. The npx and OpenClaw installation instructions likewise reference mutable upstream content without an immutable release identifier.

Consequently, the code reviewed during this audit is not sufficient to determine the code that users will ultimately install and execute. A compromised upstream publisher account, package registry, repository, release pipeline, or transitive dependency could cause a later installation to retrieve attacker-controlled content. Package installation hooks and imported SDK code may execute with the privileges of the user running the agent.

The installation is documented rather than automatically invoked by SKILL.md, so exploitation requires a user or agent to follow one of the installation instructions.

Attack Path

  1. An attacker compromises the upstream CellCog package, skill repository, publisher credentials, release pipeline, or a transitive dependency.
  2. The attacker publishes a malicious release under the package or skill identifier referenced by SKILL.md. 3 ...[truncated 1311 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every dependency and skill to an exact, reviewed version rather than using mutable package names or upgrade-to-latest commands.
  2. Replace pip install -U cellcog with installation from a version-locked requirements file using cryptographic hashes, such as pip install --require-hashes -r requirements.txt.
  3. Pin the npx and OpenClaw skill references to immutable releases or commit digests when those ecosystems support it.
  4. Maintain a lockfile covering all transitive dependencies and review dependency changes before updating it.
  5. Verify package provenance through registry signatures, trusted-publisher metadata, checksums, or software attestations.
  6. Avoid automatic upgrades in production and agent environments. Test updates in an isolated environment before deployment.
  7. Run the dependency in a sandbox with minimal filesystem and network access.
  8. Supply CELLCOG_API_KEY only at runtime through a restricted secret manager, use a task-scoped key where supported, and rotate the key after suspected dependency compromise.
  9. Add a privacy warning instructing users not to submit unnecessary credentials, tax records, portfolio details, or other sensitive financial data to third-party services.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill offers portfolio optimization, tax planning, and personal-finance guidance that could materially influence real financial decisions, but it does not include a clear disclaimer that outputs are informational and may be incomplete or inaccurate. In this context, users may over-trust generated advice and act on unsuitable or erroneous recommendations, leading to financial or tax harm.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to install or run tooling via npx skills add ... without pinning an exact package version. This allows supply-chain drift: a later malicious or compromised package release could be fetched and executed at install time, exposing users to arbitrary code execution or credential theft.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.