Back to skill

Security audit

find-b2b-leads

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed B2B lead-sourcing workflow that uses Cargo and Sales Navigator, with cost guidance and no hidden local code in the artifact.

Before installing, be aware that this uses an external Cargo CLI, requires account login, may store authentication locally through that CLI, and can spend Cargo credits when lead searches run. Confirm the target profile, limit, provider access, and estimated credit use before approving larger batches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad phrases such as "build me a list of leads" and "source leads for my outbound," which are common, high-level requests that may appear in contexts not specifically intended for this skill. That increases the chance of accidental invocation, causing the agent to run lead-sourcing actions, consume credits, and potentially initiate external tool usage when a more appropriate skill or a clarifying question should have been used.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.