Back to skill

Security audit

cargo-gtm

Security checks across malware telemetry and agentic risk

Overview

This sales-enrichment skill is not malicious, but it can move personal lead data into CRMs, sequencers, ad platforms, LinkedIn actions, and recurring workflows with some side effects under-scoped.

Review this skill before installing in a production Cargo workspace. Use it only with authorized B2B data, enforce basis/suppression/relevance checks, treat sequencer, CRM, ad, LinkedIn, webhook, and scheduled-play steps as live external side effects, and require a preview with destination, fields, record count, and approval before any write or recurring run. Avoid consumer-social scraping and minimize personal or confidential fields sent to LLM and enrichment providers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (32)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill declares no permissions, yet its documented behavior clearly depends on external CLI execution, authenticated workspace access, and numerous networked data providers. That mismatch can bypass user/admin expectations and policy enforcement, causing the agent to perform networked and environment-backed actions without explicit consent boundaries being visible in the manifest.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The guide states 'Nothing here sends' and frames outputs as merely variables for a user's sequencer, but later provides concrete instructions to push enriched and personalized leads into sequencers and CRMs. This mismatch can mislead operators about when data leaves the system and may cause users to send or sync prospect data to third-party platforms without recognizing that this is an external write step with compliance and privacy implications.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The document claims the output is only variables for the user's own sequencer, yet it also documents direct sequence enrollment and CRM write actions. That inconsistency increases the risk of unsafe operator assumptions, especially in a sales-outreach skill where enriched personal data and generated messaging may be propagated into external automation systems.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The guidance explicitly suggests using specialized scrapers or consumer-social sourcing for goals like TikTok creators and niche web data when the documented B2B priority stack cannot serve the request. That broadens the skill beyond its stated consent-gated B2B scope and creates a path for operators to collect personal or scraped data without the manifest's stated safeguards, increasing privacy, compliance, and abuse risk.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The guide explicitly recommends 'Visitor de-anonymization' via snitcher.searchSessions → cargo.matchProspect without any nearby privacy, consent, or lawful-basis guardrails. In a B2B prospecting skill, that creates a meaningful risk of enabling identification and enrichment of website visitors in ways that may violate privacy expectations, internal policy, or applicable law if the operator lacks notice and authorization.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The sequencer integration section encourages pushing personalized lists to outbound platforms but does not include a clear warning that personalized lead data will be transferred into external systems that may initiate or facilitate outreach. In this context, omission of that warning can lead to accidental misuse, privacy/compliance violations, or unauthorized campaign activation workflows.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The CRM sync section omits a direct notice that enriched and scored prospect data will be written into external CRM records. Because this skill handles lead intelligence and outreach preparation, users may unintentionally persist inferred or generated data into production systems without understanding the governance, retention, and access consequences.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The playbook explicitly recommends reverse-email lookup to recover LinkedIn and company identity from an email address, including for webforms and session-derived sources, but does not pair that guidance with a privacy/legal-use warning or a requirement to confirm consent basis before enrichment. In a GTM skill that handles personal contact data, this creates a realistic risk of de-anonymizing individuals and expanding personal profiles in ways that may violate policy, user expectations, or applicable privacy rules if used without strict gating.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The playbook documents `addContactToSequence` as a normal own-key action and frames sequence handoff as a standard activation path, but it does not explicitly warn that this can place contacts into live outbound sequences and trigger real emails. In a GTM skill that handles contact enrichment and CRM sync, that omission increases the risk of accidental outreach, policy violations, or emailing unverified/unconsented contacts if an agent or user treats the action as a routine sync step.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The playbook includes prospect enrichment and monitoring workflows for identified individuals, including contact details, LinkedIn profile data, posts, and job-change events, but the examples themselves do not surface any privacy, consent, suppression-list, or lawful-basis guardrails at the point of use. In a GTM skill that directly handles personal data, omission of those checks in provider-specific instructions increases the chance that downstream agents will operationalize people-data enrichment and monitoring without enforcing the higher-level acceptable-use constraints.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The playbook documents actions like profile visits, follows, connection requests, likes, and comments that execute as a real connected LinkedIn identity and create externally visible effects, but the action descriptions do not consistently include an immediate, explicit warning that these are user-visible outbound actions. In a GTM automation skill, this increases the risk that an agent invokes them as if they were passive enrichment steps, causing unintended contact, reputational harm, or policy violations through automated activity on a user's account.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The playbook explicitly promotes reverse-phone identification as a supported use case but provides no privacy, consent, or legal-use warning at the point of use. In a lead-generation skill, resolving a person from a phone number can enable intrusive identification, contact enrichment, and misuse of personal data, especially if the number was collected outside a clear B2B consent workflow.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The backfill examples explicitly process personal identifiers such as email, LinkedIn URLs, phone numbers, names, company, and location, but the playbook section itself provides no immediate privacy, lawful-basis, minimization, or sensitivity guardrails. In a GTM skill that performs enrichment at scale, omission of those warnings can normalize unsafe handling of personal data and lead operators to enrich or combine PII without checking consent basis, suppression rules, or jurisdictional restrictions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The playbook explicitly states that every model has live internet access and that users may attach their own Perplexity API key, but it does not warn operators that prompts and embedded record data will be transmitted to a third-party provider and may be processed outside Cargo. In a GTM skill that routinely handles account/contact enrichment and outreach context, this omission increases the risk that users send personal data, confidential CRM notes, or other sensitive business information to an external service without realizing the privacy and compliance implications.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The examples and usage guidance encourage web-grounded company research and personalization workflows, including per-record prompts that could easily incorporate contact or CRM context, but they do not explicitly prohibit sending sensitive personal, confidential, or regulated data to the external provider. Because this skill is designed for B2B contact research and outreach, operators may over-share lead details or internal sales context in prompts, creating unnecessary third-party disclosure and compliance exposure.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The playbook explicitly supports lookup of personal contact channels and US healthcare provider NPI data, which can implicate sensitive personal and regulated data handling, yet this file provides no local warning, minimization guidance, or handling constraints. In a GTM skill that operationalizes enrichment and outreach, omission of those safeguards makes misuse easier and increases the chance of non-compliant collection, enrichment, or downstream activation of sensitive records.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The playbook operationalizes large-scale lead and account sourcing, extraction from saved searches, and recurring pulls of lead data, but the section itself contains no privacy, consent, or suppression guardrails at the point of use. In a GTM skill that directly handles personal data, this omission can cause downstream agents to over-collect or repeatedly process personal information without validating lawful basis, minimization, or outreach constraints.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The playbook describes de-anonymizing website visitors and syncing identified companies into workspace models, but it does not prominently warn about privacy, consent, notice, and jurisdiction-specific tracking obligations tied to visitor identification. Even though the broader skill metadata mentions consent gating, this provider-specific document could still encourage deployment of tracking-based identification without making the compliance-sensitive nature of the data handling explicit at the point of use.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The playbook instructs users to send email addresses and related metadata to a third-party verifier (ZeroBounce) but does not include a clear privacy notice, data-sharing warning, or handling constraints at the point of use. In a B2B prospecting workflow, this can lead to operators transmitting personal data to an external processor without confirming lawful basis, vendor approval, retention terms, or regional transfer requirements.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The recipe directs operators to store customer account and contact data in world-accessible temporary paths such as /tmp without any guidance on access controls, cleanup, retention, or avoiding shared hosts. In a GTM skill, those files can contain business-sensitive account lists and contact data, so local disclosure through multi-user systems, backups, shell history, or leftover temp files is a realistic risk.

Missing User Warnings

High
Confidence
94% confidence
Finding
The workflow sends customer domains and prospective contact attributes to third-party providers like Sales Navigator, PeopleDataLabs, and enrichment services, but does not remind the operator to verify contractual approval, data-processing basis, or tenant policy before sharing customer-linked data externally. Given this skill explicitly handles B2B contacts and buying committees, silent transfer to external vendors can create privacy, confidentiality, and compliance exposure, especially when customer status itself may be sensitive commercial information.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This recipe operationalizes identifying named individuals at target companies, finding their work email addresses, and verifying deliverability, but the steps shown do not require an explicit consent, lawful-basis, or suppression-list check at the point of execution. In a B2B prospecting skill, that omission is dangerous because it enables large-scale personal-data processing and outreach preparation that can violate privacy, anti-spam, or platform-use rules if downstream safeguards are skipped or not enforced.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The recipe instructs the agent to write prospect data to internal models, export CSVs, and push records into external CRMs without an explicit user-facing warning or confirmation before modifying or transmitting data. That creates a risk of unintended data propagation, over-sharing of personal/business data, and irreversible downstream syncing into systems of record.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The recipe recommends downstream actions that modify external systems and send data to third parties (HubSpot, Slack, webhooks, sequencers) without an explicit confirmation/approval step or a warning that these actions transmit company data outside the current workspace. In an agent setting, this increases the chance of unintended CRM writes, notifications, or outreach-triggering actions based on auto-suggested next steps, especially because the skill is designed to operationalize GTM workflows.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The recipe sends personal contact identifiers such as work email, LinkedIn URL, and company-domain-linked identity data to a third-party enrichment provider without an explicit privacy/compliance checkpoint in the procedure itself. Although the broader skill description mentions consent basis and suppression controls, this specific recipe can be executed as written on customer or prospect contact segments, creating a realistic risk of unauthorized processing, policy violations, or over-sharing if the operator assumes the recipe is self-contained.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/common.ts:188

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/common.ts:165