Back to skill

Security audit

Cold Email Prospecting Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides RevoScale contact-lookup instructions for sales prospecting, with privacy-sensitive use that is disclosed and purpose-aligned but should be used carefully.

Install only if you intend to use RevoScale for lawful, authorized business outreach. The skill may retrieve personal contact details from LinkedIn-profile-based lookups, so users should follow consent, privacy, anti-spam, and workplace policies before requesting or using those results.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is explicitly designed to retrieve personal emails and mobile phone numbers from external APIs, but it does not clearly warn users that personal contact data may be fetched, exposed, and processed. In a prospecting context, this increases privacy, consent, and compliance risk because users may trigger collection of sensitive personal data without informed awareness or appropriate gating.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description advertises broad capabilities to find personal emails, mobile phone numbers, and verify deliverability for cold outreach, but it provides no limiting trigger conditions, user-scope boundaries, or usage constraints. In an agent ecosystem, this kind of open-ended prospecting skill can be invoked in contexts beyond legitimate sales workflows, increasing the risk of privacy-invasive data collection, unsolicited outreach, and abuse at scale.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The instruction to 'Always offer' email verification pushes an additional action related to outreach without clear user opt-in, which can nudge the agent into extending processing beyond the user's original request. While not directly exfiltrating data, it creates an autonomy and privacy-boundary issue by encouraging extra contact-data handling and outreach-oriented behavior by default.

Static analysis

No suspicious patterns detected.