T08 · Insecure Dependencies
- Location
SKILL.md:152- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 152–156
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Mediumtext **Claude Code, Cursor, Codex + 70 more agents:** `npx skills add cellcog/skills --skill cellcog` **OpenClaw:** `openclaw skills install @cellcog/cellcog` **CellCog plugin users:** run `/cellcog-setup` (or `/cellcog:cellcog-setup` depending on your tool) **Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.Technical Analysis
The setup instructions direct users to retrieve and install third-party packages without specifying reviewed versions, immutable commit hashes, package hashes, or lockfiles. The
pip install -Ucommand explicitly selects an available newer release, while thenpxand OpenClaw installation commands similarly reference mutable package identifiers.Consequently, the code executed by users can differ from the content available when this skill was audited. If a package registry, repository, publisher account, or future upstream release is compromised, malicious package code or installation hooks could execute under the privileges of the user running these commands.
This is a supply-chain weakness rather than evidence that the currently referenced CellCog packages are malicious.
Attack Path
- An attacker compromises an upstream publisher account, package repository, registry entry, or release process associated with a referenced dependency.
- The attacker publishes a malicious release under the existing mutable package identifier.
- A user follows one of the documented installation commands.
- The package manager retrieves the malicious release because no reviewed version, hash, or immutable revision is enforced.
- Installation hooks, setup logic, plugin initialization, or subsequently imported SDK code executes with the installing user's privileges.
- T ...[truncated 719 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every dependency to a reviewed, exact version rather than using mutable latest-version references.
- Where supported, reference an immutable commit digest or package artifact checksum.
- Replace automatic upgrade instructions such as
pip install -U cellcogwith an exact version and hash-verified installation. - Provide a lockfile or requirements file containing approved versions and cryptographic hashes.
- Document the expected package registry and repository domains so users can detect source substitution.
- Verify package signatures or provenance attestations where the ecosystem supports them.
- Review new releases before updating documented versions.
- Perform installation and execution in a least-privilege environment with restricted filesystem, credential, and network access.
- Avoid exposing
CELLCOG_API_KEYor unrelated credentials to installation scripts when they are not required during installation.
