Back to skill

Security audit

track-job-changes

Security checks for vulnerabilities and agentic risk

Overview

The core job-change lookup is coherent, but the skill adds vendor attribution, local agent-config checks, and an unrelated GitHub starring workflow that users should review first.

Install only if you are comfortable sending contact emails and company domains to Cargo/Waterfall, installing a mutable latest Cargo CLI package, and allowing Cargo session attribution. Decline or skip the GitHub starring step unless you intentionally want the agent to modify your GitHub account, and consider removing the unrelated star marker behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
94% confidence
Finding

The skill inspects ~/.claude/plugins/installed_plugins.json, which accesses agent-local configuration to detect installed plugins. Reading agent config directories is sensitive because it exposes information about the user's tooling and environment beyond what is required for job-change tracking, and can be repurposed for fingerprinting or conditional behavior.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "track-job-changes" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: track-job-changes
description: "Detect which of your contacts have changed jobs, and where they went, powered by Cargo. Triggers: \"who changed jobs\", \"track job changes in my CRM\", \"did any of my contacts move companies\", \"alert me when a champion leaves\", \"find people who recently started a new role\", \"job changes\", \"job change signals\". Providers: waterfall. Skip when: you want new contacts rather than movement among existing ones — use find-b2b-leads."
version: "1.1.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill instructs use of npx skills add getcargohq/cargo-skills without pinning a specific version or commit. That makes execution dependent on the latest published package state at runtime, which can introduce supply-chain risk if the package is updated maliciously or incompatibly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The GitHub starring workflow is unrelated to the stated purpose of tracking contact job changes and asks the agent to perform an external side effect on the user's GitHub account. Even with a prompt for consent, this expands scope unnecessarily and can normalize account actions unrelated to the requested business task.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill writes a marker file under ~/.config/cargo-ai/.star-asked to persist state across sessions for a purpose unrelated to the core task. This is a local side effect outside the user's requested workflow and can accumulate hidden behavioral state without clear necessity.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill performs session/workspace attribution logging for the vendor's benefit rather than for the user's job-change detection task. This creates extra data collection and outbound state changes that are not necessary to fulfill the user request, increasing privacy and transparency concerns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.