Back to skill

Security audit

Wireframe

Security checks for vulnerabilities and agentic risk

Overview

The skill coherently describes a CellCog-backed UI prototyping workflow, with notable but user-manageable exposure from external hosting and unpinned install guidance.

Install only from the publisher/source you trust, prefer a pinned or reviewed CellCog version where possible, use a narrowly scoped API key, and avoid putting secrets, customer data, unreleased product details, or regulated information into prompts or hosted prototypes unless CellCog's access and retention terms meet your needs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:272
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill promotes generation of interactive HTML prototypes hosted on live URLs, but it does not clearly warn users that prompt contents, embedded data, mock customer information, or internal product details may be transmitted to and exposed through externally hosted artifacts. This can lead to unintended disclosure of sensitive or proprietary information, especially because users are encouraged to include realistic content and share links with stakeholders.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx skills add cellcog/skills --skill cellcog without pinning a specific package/version. This creates a supply-chain risk because npx resolves and executes code from the registry at install time, so a compromised, typo-squatted, or unexpectedly changed package could execute arbitrary code on the user's machine. In this skill context, the danger is somewhat elevated because the instructions are framed as setup guidance users may copy-paste directly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.