Back to skill

Security audit

AfrexAI Lead Hunter Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent lead-generation playbook, but it promotes autonomous collection of business contact data and unsolicited outreach without enough human approval or compliance controls.

Review before installing or enabling autopilot. Use this only with lawful, permitted B2B data sources, require human approval before any first contact or sequence send, maintain opt-out and suppression lists, and confirm that email, LinkedIn, CRM, and privacy-law obligations are satisfied for your target regions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill is explicitly designed to automate prospect discovery, enrichment, scoring, outreach, and CRM tracking, but it provides no safeguards around privacy law, consent, anti-spam compliance, or acceptable-use boundaries. In this context, an autonomous agent could collect personal data and initiate unsolicited contact at scale, creating legal, reputational, and abuse risk far beyond ordinary business automation.

Missing User Warnings

High
Confidence
98% confidence
Finding
The 'Daily Autopilot Routine' instructs the agent to send outreach emails automatically and update pipeline state without requiring human approval. That makes misuse easier because the system can perform unsolicited contact continuously and at scale, increasing spam, compliance, and operational-abuse risk if the targeting or content is wrong.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README promotes fully autonomous prospect discovery, enrichment, scoring, and outreach to external contacts without any caution about privacy, consent, lawful basis, rate limits, or human review. In a lead-generation skill, this omission is risky because users may deploy unattended workflows that collect personal data and send outreach at scale, creating privacy, compliance, and reputational harm.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation advertises autopilot mode and a cron-based daily routine that runs without human intervention, but provides no warning that unattended execution can continuously modify CRM state or trigger outreach workflows. In this context, automation increases the chance of spammy contact, propagation of bad data, and large-scale mistakes before an operator notices.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The enrichment section directs the agent to infer email addresses, verify patterns, inspect social activity, and gather personal details from multiple sources, but it omits privacy and acceptable-use constraints. This enables non-transparent profiling and collection of personal contact data that may violate platform terms, privacy expectations, or data-protection requirements, especially when combined with automated outreach.

Static analysis

No suspicious patterns detected.