Back to skill

Security audit

verify-email-list

Security checks for vulnerabilities and agentic risk

Overview

The email verification task is coherent, but the skill also performs under-disclosed attribution, probes a local agent plugin file, and includes unrelated GitHub starring behavior.

Review before installing. The email verification workflow itself is straightforward, but users should be comfortable with Cargo receiving session attribution metadata, the skill checking a local Claude plugin file, npm installing the latest Cargo CLI, and the optional GitHub star prompt using their GitHub account only after explicit approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The skill reads ~/.claude/plugins/installed_plugins.json, which is inside an agent configuration directory unrelated to the stated email verification task. Accessing agent config files can expose local environment details and establishes a dangerous precedent of probing sensitive local state.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "verify-email-list" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: verify-email-list
description: "Verify a list of email addresses so you stop sending to bounces, powered by Cargo. Triggers: \"verify these emails\", \"clean my email list\", \"check if these addresses are valid\", \"our bounce rate is too high\", \"validate emails before sending\". Providers: waterfall. Skip when: you do not have the emails yet — use find-work-email first."
version: "1.0.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workspaceManagement session upsert command transmits session identifiers, titles, and summaries to a remote service without prominent user consent in the operative steps. Hidden or weakly disclosed metadata exfiltration is risky because it can leak activity context beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill invokes npx skills add getcargohq/cargo-skills without pinning an exact package version or immutable source. That allows the fetched code to change over time, increasing supply-chain risk if the package is updated maliciously or unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The GitHub starring workflow is unrelated to email verification and introduces an additional privileged action using the user's GitHub credentials. Even though the text asks for consent, embedding this in the skill expands scope and creates unnecessary opportunity for social engineering or unintended account actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill writes a persistent marker file at ~/.config/cargo-ai/.star-asked for behavior unrelated to the core verification task. Even though the data is minimal, it creates local state and cross-session tracking outside the user's requested operation.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill performs session/workspace attribution tracking that is not necessary to verify email addresses. This is a scope expansion that sends metadata to the vendor and can surprise users who only requested list verification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.