T08 · Insecure Dependencies
- Location
SKILL.md:248- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 248
Vulnerability Type: Unpinned third-party package installation
Risk Level: MediumThe skill instructs users to install the latest available release of the
cellcogpackage without specifying an exact version or verifying its integrity:text **Manual setup:** `pip install -U cellcog` and set `CELLCOG_API_KEY`. See the **cellcog** skill for SDK reference.The package is also declared without a version constraint in the skill metadata:
yaml dependencies: [cellcog]Technical Analysis
The
pip install -U cellcogcommand resolves and installs whichever package release the configured Python package index considers current at execution time. The reviewed skill therefore does not deterministically identify the code that will be installed.A future compromised, malicious, or otherwise unsafe release could execute installation hooks or package code with the privileges of the user running the agent. The
-Uoption additionally encourages replacement of a previously reviewed version with a newer, potentially unreviewed version. No hash, lock file, exact version, signature verification, or trusted artifact location is provided.This finding does not establish that the current
cellcogpackage is malicious. The vulnerability is the unsafe, mutable dependency resolution process.Attack Path
- An attacker compromises the package publisher account, package distribution infrastructure, or a configured Python package index used by the victim.
- The attacker publishes a malicious release under the expected
cellcogpackage name. - A user follows the documented
pip install -U cellcoginstruction, or dependency handling resolves the unpinnedcellcogdeclaration. pipdownloads and installs the attacker-controlled release.- Malicious package code executes during installation or when the skill imports and invokes the SDK. 6 ...[truncated 840 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable installation command with an exact, reviewed version, such as
pip install cellcog==<reviewed-version>. - Use a lock file or constraints file containing cryptographic hashes, and install with
pip install --require-hashes -r requirements.txt. - Pin the dependency version in the skill metadata rather than declaring only
cellcog, if the metadata format supports version constraints. - Obtain packages exclusively from an explicitly configured and trusted package index. Avoid untrusted mirrors or indexes that permit dependency confusion.
- Review each dependency update before changing the pin, including transitive dependencies and package ownership changes.
- Install and run the dependency in an isolated virtual environment or container with minimal filesystem and network permissions.
- Keep
CELLCOG_API_KEYnarrowly scoped, rotate it periodically, and avoid exposing it to installation steps or processes that do not require it. - Remove
-Ufrom routine setup instructions so installation does not silently move to an unreviewed release.
- Replace the mutable installation command with an exact, reviewed version, such as
