Back to skill

Security audit

Alpha Ceema B2B Outreach

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed sales outreach helper that looks up company data from Alpha Ceema and drafts emails, but users should review privacy and anti-spam obligations before using it at scale.

Install only if you are comfortable with the agent querying the Alpha Ceema company database and using returned company information to draft outreach. Review generated emails before sending and make sure any bulk sales workflow complies with applicable privacy, data-licensing, and anti-spam rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to query a third-party company database and use the returned data to generate personalized outreach, but it does not disclose this behavior or warn users that external data will be accessed and incorporated into messages. This creates a transparency and privacy risk: users may unknowingly trigger third-party data processing and produce outreach content based on external profiles without understanding the source or compliance implications.

Static analysis

No suspicious patterns detected.