Back to skill

Security audit

find-b2b-leads

Security checks for vulnerabilities and agentic risk

Overview

This lead-finding skill has a coherent core purpose, but it adds review-worthy tracking, local agent-config inspection, and promotional GitHub account actions outside the lead-search task.

Review before installing. The lead-search function is plausible, but only proceed if you are comfortable installing the Cargo CLI, signing into Cargo, spending Cargo credits after approval, allowing a local check of installed Claude plugins, and declining the optional GitHub star or full-pack install unless you explicitly want those actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The skill reads ~/.claude/plugins/installed_plugins.json to inspect the agent's local configuration and make routing decisions. Accessing agent config directories is sensitive because it reveals installed tools/plugins and normalizes filesystem inspection outside the skill's stated purpose, which can be repurposed for environment discovery or targeting.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "find-b2b-leads" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like 'build me a list of leads' and 'lead sourcing', which can cause the skill to auto-activate in contexts where the user did not specifically request this tool. Over-broad invocation increases the chance of unintended external API calls, spending credits, and processing user data without sufficiently clear consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: find-b2b-leads
description: "Find B2B leads by job title, company, and keyword, and return them as a structured list, powered by Cargo. Triggers: \"find 50 VPs of Sales at fintech companies\", \"build me a list of leads\", \"who are the heads of engineering at Series B startups\", \"get me prospects matching this profile\", \"source leads for my outbound\", \"build a b2b lead list\", \"lead sourcing\". Providers: salesNavigator. Skip when: you need companies rather than people — use build-tam-list; or you already have the people and need contact details — use find-work-email."
version: "1.1.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill invokes npx skills add getcargohq/cargo-skills without pinning an exact package version or commit, so future executions may fetch changed code from the registry. That creates a supply-chain risk where an agent could install and trust unexpectedly modified tooling outside the reviewed skill contents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The GitHub starring flow is unrelated to the stated purpose of finding B2B leads and asks the agent to perform an external account action on the user's behalf. Even with a yes/no prompt, bundling promotional account actions into an operational skill violates least privilege and increases the chance of unintended or socially engineered side effects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill writes ~/.config/cargo-ai/.star-asked to persist local state unrelated to lead-finding. While low severity, this creates durable side effects on the host filesystem for promotional workflow control and demonstrates unnecessary persistence outside the skill's core function.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill performs session/workspace attribution tracking that is not necessary to return B2B leads. This causes extra data disclosure and external state mutation beyond user intent, and it also conditions behavior on local environment inspection, which broadens the skill's access footprint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.