T08 · Insecure Dependencies
- Location
SKILL.md:218- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13 and 218–221
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumVulnerable Code
yaml dependencies: [cellcog]markdown ## If CellCog is not installed **Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog` **OpenClaw:** `openclaw skills install @cellcog/cellcog` **CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool) **Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.Technical Analysis
The skill declares and recommends installing the
cellcogdependency without an exact version, cryptographic hash, verified signature, or lockfile. Thepip install -U cellcogcommand explicitly selects the latest package version available at installation time. Thenpxand OpenClaw installation instructions likewise reference mutable upstream content without an immutable release identifier.Consequently, the code reviewed during this audit is not sufficient to determine the code that users will ultimately install and execute. A compromised upstream publisher account, package registry, repository, release pipeline, or transitive dependency could cause a later installation to retrieve attacker-controlled content. Package installation hooks and imported SDK code may execute with the privileges of the user running the agent.
The installation is documented rather than automatically invoked by
SKILL.md, so exploitation requires a user or agent to follow one of the installation instructions.Attack Path
- An attacker compromises the upstream CellCog package, skill repository, publisher credentials, release pipeline, or a transitive dependency.
- The attacker publishes a malicious release under the package or skill identifier referenced by
SKILL.md. 3 ...[truncated 1311 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every dependency and skill to an exact, reviewed version rather than using mutable package names or upgrade-to-latest commands.
- Replace
pip install -U cellcogwith installation from a version-locked requirements file using cryptographic hashes, such aspip install --require-hashes -r requirements.txt. - Pin the
npxand OpenClaw skill references to immutable releases or commit digests when those ecosystems support it. - Maintain a lockfile covering all transitive dependencies and review dependency changes before updating it.
- Verify package provenance through registry signatures, trusted-publisher metadata, checksums, or software attestations.
- Avoid automatic upgrades in production and agent environments. Test updates in an isolated environment before deployment.
- Run the dependency in a sandbox with minimal filesystem and network access.
- Supply
CELLCOG_API_KEYonly at runtime through a restricted secret manager, use a task-scoped key where supported, and rotate the key after suspected dependency compromise. - Add a privacy warning instructing users not to submit unnecessary credentials, tax records, portfolio details, or other sensitive financial data to third-party services.
