Back to skill

Security audit

B2B Contact Enrichment

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed FinalScout contact-enrichment integration, but users should treat bulk lookups, exports, webhooks, and metadata as personal-data sharing.

Install only if you intend to use FinalScout for B2B contact enrichment and have authority to submit the relevant names, domains, LinkedIn URLs, article URLs, and metadata. Be especially careful with bulk CSVs, CRM identifiers in meta_data, public export links, personal/generic email options, and webhook URLs, because those can share personal or business data outside your local environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README encourages unconstrained natural-language invocation, which can cause the skill to activate on loosely related prompts and send contact data or URLs to the external FinalScout service without sufficiently explicit user intent. In a skill that performs outbound API calls and supports bulk processing, broad activation guidance increases the risk of accidental data disclosure and unintended third-party processing.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The documentation does not clearly warn users that names, company domains, LinkedIn URLs, article URLs, and optional metadata are transmitted to FinalScout, and that results may also be exported or sent to webhooks. Because this skill handles contact-enrichment data and supports bulk uploads, missing disclosure can lead to users unintentionally sending sensitive business or personal data to external systems.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly enables finding and exporting professional email addresses but does not warn users about privacy, consent, or acceptable-use obligations. In a contact-enrichment context, this omission increases the chance of misuse for unsolicited outreach, unauthorized processing of personal data, or non-compliant export of personal information.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The webhook section instructs users to send task results, contact data, and metadata to arbitrary third-party URLs without emphasizing the sensitivity of that data or the risks of external disclosure. This can lead to accidental exfiltration of personal data and internal identifiers, especially because metadata is echoed back and could contain CRM IDs or other sensitive correlation fields.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.