Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md | node references/rsc.mjs legacyId --dedupe id \
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed, read-only Angi data helper, but users should be careful because it relies on a browser-paired fetch tool that can use the active Angi session when explicitly paired.
Install only if you trust @fetchproxy/cli and the ContextMint Bridge extension. Pair only www.angi.com for public directory lookups, and do not pair my.angi.com unless you intentionally want the agent to read your signed-in Angi account pages. Treat extracted review/profile output as potentially personal data and follow Angi's terms.
Referenced artifact was not completely inspected
| node references/rsc.mjs legacyId --dedupe id \
Referenced artifact was not completely inspected
| node references/rsc.mjs legacyId --dedupe id \
Referenced artifact was not completely inspected
| node references/rsc.mjs legacyId --dedupe id \
The skill’s declared purpose is public Angi directory lookup, but it also includes explicit instructions to access authenticated data on my.angi.com via the user’s existing browser session. That expands the skill from public scraping into session-bound account data access, creating a risk of unnecessary exposure of personal account information and privilege creep beyond the stated use case.
The skill includes capability to read authenticated account pages and JSON endpoints even though its stated purpose is finding pros, ratings, reviews, and taxonomy data. This mismatch is dangerous because users or higher-level agents may invoke the skill expecting only public directory access, while the implementation can silently leverage an authenticated browser tab to retrieve private user data.
The file instructs users to fetch and extract review records and provider details, including fields like userName, address components, comments, and business identifiers, but does not include any warning about handling personal data or respecting site terms. Under the markdown-file criteria, this is a missing warning for behavior that could affect privacy or user data handling.
The note frames the capability boundary as primarily public data plus the user's own account data, but elsewhere the skill relies on browser-tab session context and Cloudflare-cleared browsing state to fetch content. This is not a direct contradiction for the directory pages, but the wording understates that the skill's effective access is whatever the paired browser session can read on the covered hosts, including authenticated surfaces.
No suspicious patterns detected.