Back to skill

Security audit

track-funding-rounds

Security checks for vulnerabilities and agentic risk

Overview

This funding-tracking skill performs the advertised Cargo lookup, but it also includes extra attribution and GitHub starring behavior that goes beyond the core task.

Review before installing. The core funding lookup is understandable, but users should be comfortable with Cargo receiving queried company domains, with persistent Cargo login/workspace state, and with the extra non-core attribution and GitHub starring instructions. Avoid running the optional broader-pack install unless you trust the publisher and version source.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The command reads ~/.claude/plugins/installed_plugins.json from the agent configuration directory to infer local plugin state. Accessing unrelated local config expands the skill's privileges beyond its stated funding-round purpose and can expose environment details or normalize probing of sensitive agent state.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "track-funding-rounds" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill requires signing into cargo-ai and creating an account/workspace, which establishes persistent authenticated state on the machine. Persistent session creation is not inherently malicious, but it does create ongoing access and data linkage beyond the immediate task, especially when the skill does not clearly explain token/session storage and lifecycle.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: track-funding-rounds
description: "Track which companies recently raised funding, with round, amount, and investors, powered by Cargo. Triggers: \"who just raised funding\", \"companies that raised a Series A\", \"track funding rounds in my market\", \"alert me when a target account raises\", \"find recently funded startups\". Providers: cargo. Skip when: you want general company data rather than funding — use enrich-company-data."
version: "1.0.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to send company domains and potentially account lists to an external service (cargo-ai) but does not clearly warn about data sharing, retention, or sensitivity considerations. In a sales/CRM context, those inputs may be proprietary target-account data, so undisclosed transmission can create privacy, confidentiality, or compliance issues.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill recommends running npx skills add getcargohq/cargo-skills without pinning an exact version. That causes execution of whatever package version is current at install time, which creates a supply-chain risk if the package is updated maliciously or unexpectedly. In this context the command is optional and not required for the core funding-round task, so it is unnecessary additional exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill includes logic to prompt for and perform a GitHub star action, which is unrelated to tracking funding rounds and uses the user's authenticated GitHub context for the vendor's benefit. Even with a consent prompt, this broadens the skill's behavior into account-affecting actions outside the stated purpose and creates social-engineering and trust-boundary concerns.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill writes ~/.config/cargo-ai/.star-asked to persist state across runs for a non-core GitHub-star prompt. This creates local persistence unrelated to funding analysis and normalizes filesystem writes for marketing behavior rather than user task completion.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill performs workspace/session attribution tracking by reading local plugin state and sending a session upsert to Cargo. This is outside the core user goal of funding discovery and introduces extra telemetry collection and local-environment inspection that users may not expect from the described functionality.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.