Back to skill

Security audit

lead-generating

Security checks for vulnerabilities and agentic risk

Overview

This lead-management skill matches its stated purpose, but it asks for a powerful Supabase service-role key and has tenant-scoping gaps around sensitive CRM data.

Review carefully before installing. Use a narrowly scoped Supabase credential or backend RPC/API instead of a broad service-role key, add explicit consent before capturing contact details or sending auto-replies, define retention/redaction rules for conversation logs, and confirm tenant filters protect every read, update, and delete path.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:11
Finding

Use of an Overprivileged Supabase Service-Role Credential

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/api.ts:242
Finding

Missing Tenant Constraint in Privileged Lead Queries

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:15
Finding

Unpinned Package Execution Through npx Installation Command

Content
View full analysis
Remediation
View remediation
install lead-inbox-automator ``` 2. Publish and verify package integrity hashes or signed provenance for the installer and skill package. 3. Use a trusted, explicitly configured registry and a lockfile where supported. 4. Review installer lifecycle scripts and transitive dependencies before recommending execution. 5. Run installation under a low-privilege account in an isolated environment without production secrets. 6. Establish a controlled upgrade process so new installer versions are reviewed before documentation is updated. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is explicitly designed to capture leads, store them in Supabase, and trigger automated email workflows, but the README does not prominently warn that user conversation content and contact details may be transmitted to third-party systems. In a lead-management context, this omission increases the chance of collecting or forwarding personal data without adequate notice, consent, or minimization.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to execute npx clawdhub install lead-inbox-automator without pinning a specific version. This creates a supply-chain risk because future or compromised package releases could be fetched and executed implicitly, especially dangerous in an installation path that users are likely to copy-paste directly.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README recommends logging all agent replies with addConversation(), which encourages retaining full conversation content in persistent storage. In this skill's context, those messages may contain personal data, sensitive requests, or regulated business information, increasing exposure in the event of overcollection, unauthorized access, or later misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly captures lead contact data, stores it in Supabase, and triggers Make.com email automation, but the description does not clearly warn users that personal data will be transmitted to external services and that an automated outbound email will be sent. This creates a meaningful privacy and consent risk, especially because agents may invoke createLead in the background based on conversational context without the end user understanding that their email, name, phone, and message metadata are being shared and acted upon.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest description describes general lead inbox automation behavior but does not specify narrow activation conditions, trigger phrases, or exclusion boundaries. For a manifest file, this can make invocation scope ambiguous and increase the chance of unintended activation in contexts involving generic lead or inbox tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The deleteLead method deletes records from the leads table, which is an irreversible data-affecting operation. Although the docstring says "use with caution," the code itself provides no confirmation prompt, user-facing warning, or safeguard before executing the deletion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file is primarily written in German, but the automation diagram includes the Chinese term "实时" with no justification or opt-in. This creates an unexplained locale inconsistency in user-facing documentation, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The runtime dependency uses a caret version range, which allows automatic installation of newer minor and patch releases. This can introduce supply-chain risk if an upstream release is compromised or contains a breaking security-relevant change, especially because this package likely handles CRM and inbox automation data.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"author": "Developer",
  "license": "MIT",
  "dependencies": {
    "@supabase/supabase-js": "^2.39.0"
  },
  "devDependencies": {
    "typescript": "^5.3.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"@supabase/supabase-js": "^2.39.0"
  },
  "devDependencies": {
    "typescript": "^5.3.0"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
64% confidence
Finding

The description says the email is used for "auto-reply," which suggests user-facing generated communication, but the schema provides no indication that language or locale is user-selected or configurable. Because policy violations can appear in config text, this may reflect a default communication behavior that does not offer language choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest-format JSON schema states that "automation triggers on 'new'" but does not explain what automation runs, when it does not run, or any limiting conditions. In a manifest-like file, this is an ambiguous activation description that could lead to unintended or overly broad downstream invocation behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.