Back to skill

Security audit

Databar MCP

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Databar MCP workflow guide for paid data enrichment, lead research, tables, and exports, with privacy and spending caveats users should still manage carefully.

Install only if you intend to connect a Databar account and spend Databar credits on enrichment workflows. Before using contact discovery, social scraping, scheduled syncs, or CRM exports, confirm you have permission and a lawful basis, review provider/platform terms, and ask the agent to price the run and get explicit approval for exports, schedules, and any delete operation.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README explicitly promotes scraping, contact enrichment, and export workflows but only provides a general legal disclaimer later, without clear, actionable warnings at the point of use about privacy, consent, permissible data use, or downstream harm. In an agent skill context, this can normalize or automate privacy-impactful collection and outreach behavior, increasing the risk of misuse or non-compliant processing of personal data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.