Back to skill

Security audit

Travel Planning

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its travel-planning purpose, but its setup uses mutable third-party install commands that should be reviewed before installation.

Install only if you trust the CellCog publisher and are comfortable running unpinned package/skill installation commands. Prefer a pinned version or verified source, and avoid exposing unrelated credentials or sensitive local files to the environment where the CellCog package and API key are available.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:152
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 152–156
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

text
**Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog`
**OpenClaw:** `openclaw skills install @cellcog/cellcog`
**CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool)
**Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.

Technical Analysis

The setup instructions direct users to retrieve and install third-party packages without specifying reviewed versions, immutable commit hashes, package hashes, or lockfiles. The pip install -U command explicitly selects an available newer release, while the npx and OpenClaw installation commands similarly reference mutable package identifiers.

Consequently, the code executed by users can differ from the content available when this skill was audited. If a package registry, repository, publisher account, or future upstream release is compromised, malicious package code or installation hooks could execute under the privileges of the user running these commands.

This is a supply-chain weakness rather than evidence that the currently referenced CellCog packages are malicious.

Attack Path

  1. An attacker compromises an upstream publisher account, package repository, registry entry, or release process associated with a referenced dependency.
  2. The attacker publishes a malicious release under the existing mutable package identifier.
  3. A user follows one of the documented installation commands.
  4. The package manager retrieves the malicious release because no reviewed version, hash, or immutable revision is enforced.
  5. Installation hooks, setup logic, plugin initialization, or subsequently imported SDK code executes with the installing user's privileges.
  6. T ...[truncated 719 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin every dependency to a reviewed, exact version rather than using mutable latest-version references.
  • Where supported, reference an immutable commit digest or package artifact checksum.
  • Replace automatic upgrade instructions such as pip install -U cellcog with an exact version and hash-verified installation.
  • Provide a lockfile or requirements file containing approved versions and cryptographic hashes.
  • Document the expected package registry and repository domains so users can detect source substitution.
  • Verify package signatures or provenance attestations where the ecosystem supports them.
  • Review new releases before updating documented versions.
  • Perform installation and execution in a least-privilege environment with restricted filesystem, credential, and network access.
  • Avoid exposing CELLCOG_API_KEY or unrelated credentials to installation scripts when they are not required during installation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to run npx skills add cellcog/skills --skill cellcog without pinning a specific package or version. This creates a supply-chain risk because npx will resolve and execute whatever package version is current at install time, so a compromised upstream package, typo-squatted dependency, or malicious update could execute untrusted code on the user's machine.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown/manifest content describes activation scope in very general terms such as 'vacation planning' and 'travel research,' which overlap with common user requests. It does not provide explicit trigger phrases, constraints, or negative examples to clarify when this skill should or should not be invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

For markdown files, warnings should disclose behaviors that may affect user data or system state. The document states that the skill 'delivers complete itineraries as beautiful PDFs or interactive dashboards' but does not warn users that artifacts may be generated or written as part of the workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.