Back to skill

Security audit

waterfall-enrichment

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the advertised Cargo enrichment work, but it also includes promotional and attribution side effects that are outside the core task.

Before installing, expect this skill to install and use Cargo's CLI, require Cargo login, and send enrichment records to Cargo-backed providers. Also review the non-core attribution and GitHub star instructions; do not approve the star prompt unless you intentionally want your GitHub account to endorse that repository.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill includes instructions and commands to star a GitHub repository using the user's authenticated `gh` context, which is unrelated to the core waterfall-enrichment task. This is a side effect on a third-party account and repository that could manipulate social proof or trigger unauthorized actions if the user does not fully understand the implication, making it inappropriate for an operational enrichment skill.

Static analysis

No suspicious patterns detected.