Back to skill

Security audit

build-tam-list

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs the advertised TAM-list task, but it also adds under-scoped attribution, local agent-config checks, optional account-mutating GitHub promotion, and persistent local markers.

Install only if you are comfortable using Cargo as an authenticated third-party service, installing latest-version CLI tooling, and allowing nonessential attribution metadata. Avoid running the optional GitHub star or broader-pack install unless you explicitly want those account/install changes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:55
Finding

Automatic Upload of Agent Session Attribution Metadata

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 55–63
Vulnerability Type: Unapproved transmission of local session metadata
Risk Level: Medium

Vulnerable Code

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "build-tam-list" \
    --summary "[gtm-skills: build-tam-list] Session started from the build-tam-list standalone skill."

Technical Analysis

During setup, the Skill checks a local Claude plugin registry and, if the Cargo GTM plugin is not detected, invokes Cargo's remote workspace management functionality to create or update a session record.

This attribution operation is not required to perform the user-requested TAM search. It occurs before the core search command and has no explicit user-consent gate. When the SESSION_ID environment variable exists, its value is transmitted as the remote session identifier; otherwise, a timestamp-derived identifier is used. The static documentation identifies this operation as attribution intended to tell the Cargo team which standalone Skill initiated a workspace.

The relevant trust boundary is crossed when locally sourced Agent session metadata is sent to the remote Cargo workspace for product attribution. The code does not minimize a preexisting SESSION_ID into a purpose-specific random value or require informed opt-in before transmission.

Attack Path

  1. A user invokes the standalone build-tam-list Skill and follows its setup instructions.
  2. The local file ~/.claude/plugins/installed_plugins.json does not contain the string "cargo@gtm", or the file does not exist.
  3. The shell || branch executes automatically.
  4. If present, the local SESSION_ID environment variable is inserted into the command; otherwise, the current timestamp is used.
  5. cargo-ai workspaceManagement session upsert sends the identifier, fixed tit ...[truncated 823 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the attribution upsert from the default setup path because it is not necessary for the TAM-list operation.
  2. If attribution is retained, disclose the exact recipient, fields, and purpose, and require explicit informed opt-in before executing the command.
  3. Do not reuse the ambient SESSION_ID. Generate a random, purpose-specific attribution identifier that cannot be correlated with unrelated Agent activity.
  4. Provide a documented telemetry-free setup path and ensure declining attribution does not prevent the core Skill from functioning.
  5. Minimize retained metadata and document its retention, deletion, and access controls.
  6. Keep attribution separate from authentication and core search operations so users and Agents can reliably omit it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The skill reads from ~/.claude/plugins/installed_plugins.json, which accesses agent configuration data unrelated to the user’s TAM-list task. Reading local configuration can reveal installed tools, environment details, or other sensitive metadata and establishes a precedent for unauthorized inspection of the agent host.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "build-tam-list" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description lists broad invocation phrases such as "find target accounts", "list building", and "build a list of companies" without tight contextual constraints. These phrases are generic enough to match everyday CRM, prospecting, or research requests and could cause unintended activation of this skill instead of a more specific one.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The skill requires signing in or creating an account and thereby establishes persistent session state with an external service. Persistent authentication is not inherently malicious, but it increases risk by extending access duration and potentially enabling future actions beyond the immediate task if not clearly consented to and scoped.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: build-tam-list
description: "Build a total addressable market list of companies filtered by industry, headcount, and geography, powered by Cargo. Triggers: \"build a TAM list\", \"how many companies match our ICP\", \"list every SaaS company in Europe under 200 employees\", \"size our addressable market\", \"find target accounts\", \"list building\", \"build a list of companies\". Providers: salesNavigator. Skip when: you want the people at those companies — use find-b2b-leads or find-stakeholders; or you want companies by tech stack — use find-companies-using-tech."
version: "1.1.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The setup flow instructs the user to create an account/workspace and send login email codes without clear privacy, data handling, or consent disclosures. This can lead users to transmit personal or corporate identifiers to a third-party service without understanding retention, workspace creation, or billing implications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill invokes npx skills add getcargohq/cargo-skills without pinning a specific version or commit, which allows whatever package version is current at execution time to run. This creates a supply-chain risk: a compromised or unexpected upstream release could execute arbitrary code in the agent environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The GitHub starring workflow is unrelated to the stated TAM-list-building purpose and asks the agent to perform an action on the user's GitHub account. Even though it requests consent, it expands scope into social/account actions and includes executable commands that mutate a third-party account and persist state locally.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill writes ~/.config/cargo-ai/.star-asked, creating persistent local state unrelated to building a TAM list. Even though the marker is small, it modifies the user's environment for promotional flow control and exceeds the minimum necessary scope of the task.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill performs session/workspace attribution tracking that is not necessary to build a TAM list. Although framed as analytics, it causes extra data submission and introduces side effects beyond the user-requested business function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.