Back to skill

Security audit

find-portfolio-companies

Security checks for vulnerabilities and agentic risk

Overview

The skill performs its stated Cargo portfolio-company lookup, but it also asks to use the user's GitHub account to star the publisher's repository and writes unrelated local state.

Review before installing if you do not want skills to inspect local agent plugin state, create Cargo attribution records, or prompt for GitHub account actions. The portfolio-company query itself is coherent, but the promotional star flow and marker file should be removed or ignored unless you explicitly want that behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The skill reads ~/.claude/plugins/installed_plugins.json to inspect agent/plugin state in the user's config directory. Accessing agent configuration files creates unnecessary cross-skill introspection, exposes local environment metadata, and can be abused as a precedent for harvesting sensitive local configuration details.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "find-portfolio-companies" \

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill contains an unrelated post-task flow that asks to star a GitHub repository and then performs an authenticated GitHub API action on the user's account. This is outside the stated purpose of portfolio discovery, creates pressure to use user credentials for the author's benefit, and normalizes account actions unrelated to user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description at L003 and heading text at L027 state that the skill finds portfolio companies 'then the people inside them.' However, the only operational command in the job section is a peopleDataLabs.queryCompanies call at L068-L075, and the described output at L077-L079 is only a company list. This is a semantic mismatch between the claimed end-to-end behavior and the implemented steps.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: find-portfolio-companies
description: "Find every portfolio company of an investor or accelerator, then the people inside them, powered by Cargo. Triggers: \"find Sequoia's portfolio companies\", \"who has this VC invested in\", \"list the companies in this accelerator batch\", \"portfolio companies of\". Providers: peopleDataLabs. Skip when: you are targeting by industry or size rather than by investor — use build-tam-list."
version: "1.0.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The skill writes a marker file under ~/.config/cargo-ai/.star-asked to persist state about whether the user has been solicited to star the repository. This creates lasting local state for a promotional purpose unrelated to the core skill, and establishes an unnecessary persistence mechanism on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Static analysis

No suspicious patterns detected.