T08 · Insecure Dependencies
- Location
SKILL.md:272- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Exposure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill coherently describes a CellCog-backed UI prototyping workflow, with notable but user-manageable exposure from external hosting and unpinned install guidance.
Install only from the publisher/source you trust, prefer a pinned or reviewed CellCog version where possible, use a narrowly scoped API key, and avoid putting secrets, customer data, unreleased product details, or regulated information into prompts or hosted prototypes unless CellCog's access and retention terms meet your needs.
SKILL.md:272Unpinned Third-Party Dependencies Create Supply-Chain Exposure
The skill promotes generation of interactive HTML prototypes hosted on live URLs, but it does not clearly warn users that prompt contents, embedded data, mock customer information, or internal product details may be transmitted to and exposed through externally hosted artifacts. This can lead to unintended disclosure of sensitive or proprietary information, especially because users are encouraged to include realistic content and share links with stakeholders.
The skill instructs users to run npx skills add cellcog/skills --skill cellcog without pinning a specific package/version. This creates a supply-chain risk because npx resolves and executes code from the registry at install time, so a compromised, typo-squatted, or unexpectedly changed package could execute arbitrary code on the user's machine. In this skill context, the danger is somewhat elevated because the instructions are framed as setup guidance users may copy-paste directly.
No suspicious patterns detected.