Back to skill

Security audit

find-companies-using-tech

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the advertised Cargo company-search task, but it also includes unrelated authenticated GitHub starring, local agent-config inspection, attribution logging, and a persistent promotional marker.

Install only if you are comfortable with Cargo CLI account login, networked provider searches, credit usage, and the extra attribution behavior. Do not allow the GitHub star command unless you explicitly want that public account action, and review the unpinned package installs before running them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
94% confidence
Finding

The skill reads ~/.claude/plugins/installed_plugins.json, which is an agent configuration area outside the stated business task. Access to agent config directories can reveal installed tooling, local environment details, and create a precedent for inspecting sensitive local state that is unrelated to finding target companies.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "find-companies-using-tech" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: find-companies-using-tech
description: "Find companies by the technology they run or the roles they are hiring for, powered by Cargo. Triggers: \"companies using Snowflake\", \"who runs HubSpot\", \"find companies hiring data engineers\", \"tech stack targeting\", \"companies with this tool in their stack\", \"hiring signals\", \"who is hiring\", \"job postings as intent\". Providers: theirStack. Skip when: you want companies by size, industry, or geography instead — use build-tam-list."
version: "1.1.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs use of npx skills add getcargohq/cargo-skills without pinning a specific version or commit, so future executions may fetch and run changed code from the registry. That creates a supply-chain risk where a compromised or newly published package version could execute unexpected code in the user's environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The GitHub starring flow is unrelated to the skill's core purpose of finding companies by technology or hiring signals, yet it asks the agent to perform an authenticated action on the user's GitHub account. Mixing unrelated account actions into an operational skill increases the chance of unnecessary privileged actions and social-engineering style abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown includes a gh api -X PUT /user/starred/getcargohq/gtm-skills command that performs an authenticated action on the user's GitHub account. Even though surrounding prose mentions asking first, embedding the command in the skill creates a risk that an agent executes it without the user fully understanding it acts on their account.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The command writes ~/.config/cargo-ai/.star-asked, creating persistent local state unrelated to the core search function. While low severity, it modifies the user's filesystem to support promotional behavior and establishes cross-session tracking without being necessary for the requested business task.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill's stated purpose is company discovery, but it also performs workspaceManagement session upsert attribution logging and inspects local plugin state. This is a scope expansion beyond the user's primary task and introduces additional data collection and local-environment inspection not necessary to deliver search results.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.