Back to skill

Security audit

story-cog

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent creative-writing wrapper for CellCog, with a normal but mutable third-party dependency install that users should treat with standard package and API-key caution.

Install CellCog from a trusted package index, preferably in an isolated environment, and consider pinning a reviewed cellcog version rather than using an automatic upgrade command. Use a narrowly scoped CELLCOG_API_KEY and avoid sending private story material or confidential context unless you are comfortable with CellCog processing it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:248
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 248
Vulnerability Type: Unpinned third-party package installation
Risk Level: Medium

The skill instructs users to install the latest available release of the cellcog package without specifying an exact version or verifying its integrity:

text
**Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.

The package is also declared without a version constraint in the skill metadata:

yaml
dependencies: [cellcog]

Technical Analysis

The pip install -U cellcog command resolves and installs whichever package release the configured Python package index considers current at execution time. The reviewed skill therefore does not deterministically identify the code that will be installed.

A future compromised, malicious, or otherwise unsafe release could execute installation hooks or package code with the privileges of the user running the agent. The -U option additionally encourages replacement of a previously reviewed version with a newer, potentially unreviewed version. No hash, lock file, exact version, signature verification, or trusted artifact location is provided.

This finding does not establish that the current cellcog package is malicious. The vulnerability is the unsafe, mutable dependency resolution process.

Attack Path

  1. An attacker compromises the package publisher account, package distribution infrastructure, or a configured Python package index used by the victim.
  2. The attacker publishes a malicious release under the expected cellcog package name.
  3. A user follows the documented pip install -U cellcog instruction, or dependency handling resolves the unpinned cellcog declaration.
  4. pip downloads and installs the attacker-controlled release.
  5. Malicious package code executes during installation or when the skill imports and invokes the SDK. 6 ...[truncated 840 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable installation command with an exact, reviewed version, such as pip install cellcog==<reviewed-version>.
  2. Use a lock file or constraints file containing cryptographic hashes, and install with pip install --require-hashes -r requirements.txt.
  3. Pin the dependency version in the skill metadata rather than declaring only cellcog, if the metadata format supports version constraints.
  4. Obtain packages exclusively from an explicitly configured and trusted package index. Avoid untrusted mirrors or indexes that permit dependency confusion.
  5. Review each dependency update before changing the pin, including transitive dependencies and package ownership changes.
  6. Install and run the dependency in an isolated virtual environment or container with minimal filesystem and network permissions.
  7. Keep CELLCOG_API_KEY narrowly scoped, rotate it periodically, and avoid exposing it to installation steps or processes that do not require it.
  8. Remove -U from routine setup instructions so installation does not silently move to an unreviewed release.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.