Back to skill

Security audit

find-stakeholders

Security checks for vulnerabilities and agentic risk

Overview

The core stakeholder-search workflow is understandable, but the skill also includes unrelated attribution and promotional account actions that need review before installation.

Review this before installing. Use it only if you are comfortable installing the Cargo CLI, logging into Cargo, sending company/person-search data through Cargo and aiArk, and spending Cargo credits. Consider removing or skipping the session-attribution snippet and the GitHub star section, and prefer pinned package versions for installs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (8)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
91% confidence
Finding

The skill reads ~/.claude/plugins/installed_plugins.json to inspect the agent's local configuration and determine plugin presence. Accessing agent config directories is sensitive because it can reveal environment details, installed tooling, and local state unrelated to the user's requested business task.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "find-stakeholders" \

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The command gh api -X PUT /user/starred/getcargohq/gtm-skills performs an authenticated action on the user's GitHub account that is not necessary for stakeholder discovery. Even with a prompt in the text, embedding account-modifying commands in a skill increases the chance of unauthorized or accidental execution and sets a dangerous precedent for unrelated privileged actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest includes broad trigger phrases such as 'find stakeholders' and 'who else should I be talking to at this account,' which may match ordinary conversation and invoke the skill unexpectedly. Over-broad activation is risky here because the skill can lead users into installing tools, authenticating accounts, and making external calls with cost and data-sharing implications.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: find-stakeholders
description: "Find the buying committee at a target account — every stakeholder matching a set of titles, seniorities, and departments, powered by Cargo. Triggers: \"find the buying committee at Acme\", \"who are the decision makers at this company\", \"find stakeholders\", \"multi-thread this account\", \"who else should I be talking to at this account\". Providers: aiArk. Skip when: you are sourcing across many companies rather than going deep on a few — use find-b2b-leads."
version: "1.0.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill instructs use of npx skills add getcargohq/cargo-skills without pinning a specific version or commit. That creates a supply-chain risk because future or compromised package updates could change behavior and execute unexpected code when the user follows the setup instructions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The repository-star workflow is unrelated to the stated purpose of finding stakeholders at a target account. Adding unrelated promotional actions inside an operational skill normalizes unnecessary account use and creates a channel for social engineering or privilege misuse.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The marker file under ~/.config/cargo-ai/.star-asked creates persistent local state unrelated to stakeholder discovery. Although low impact, persistence for a nonessential promotional feature is unnecessary and expands the skill's ability to track cross-session user behavior.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Writing ~/.config/cargo-ai/.star-asked is unrelated to the core task and creates persistent state on the local machine for a nonessential promotional workflow. While low severity, unrelated persistence broadens the skill's footprint and can be abused to track behavior or silently influence future runs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.