Back to skill

Security audit

enrich-company-data

Security checks for vulnerabilities and agentic risk

Overview

The skill performs its stated company-enrichment task, but it also adds unrelated attribution, local agent-config inspection, unpinned installs, and a GitHub star workflow that users should review before installing.

Install only if you are comfortable with Cargo CLI account use, sending company/domain data to Cargo, and possible credit usage. Review or remove the attribution block and GitHub star workflow if you want the skill limited strictly to enrichment, and prefer pinned package versions for reproducible installs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (7)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The skill reads from ~/.claude/plugins/installed_plugins.json, which accesses agent configuration data unrelated to the user's enrichment task. Access to agent config can reveal installed tools or environment details and establishes a precedent for inspecting sensitive local state without necessity.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "enrich-company-data" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary business-language requests like "fill in company data" or "what sector is this business in," which can cause unintended invocation. In context, unintended activation is more concerning because the skill can install tooling, prompt for login, create accounts, and perform batch API actions with cost and data-sharing consequences.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: enrich-company-data
description: "Enrich a list of companies with firmographics — industry, size, geography, founding year, and headquarters, powered by Cargo. Triggers: \"enrich these companies\", \"add company size and industry to my list\", \"get firmographics for these domains\", \"enrich a supplied spreadsheet of company domains once\", \"fill in company data\", \"company enrichment\", \"enrich companies\", \"what sector is this business in\", \"how big is this organisation\". Providers: cargo. Skip when: you want funding history — use track-funding-rounds; or tech stack — use find-companies-using-tech."
version: "1.1.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill recommends npx skills add getcargohq/cargo-skills without pinning a specific version or commit, which makes execution depend on whatever package version is current at install time. This creates a supply-chain risk: a compromised or unexpectedly changed upstream package could run different code than what was reviewed here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill includes instructions to ask for and perform a GitHub star action unrelated to company enrichment. Even though it requests explicit consent, it expands scope from data enrichment into modification of the user's GitHub account, creating unnecessary privilege use and increasing the chance of social engineering or accidental account actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill writes a persistent marker file in ~/.config/cargo-ai/.star-asked to track whether the user has been prompted about starring a repository. This creates local state unrelated to enrichment, persists across sessions, and is tied to an ancillary marketing action rather than the core function of the skill.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill inspects local plugin state and performs session attribution writes that are not required to enrich company data. This broadens local filesystem access and causes outbound metadata writes, increasing privacy and integrity risk beyond the minimum necessary behavior for the stated task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.