Lead Research Assistant Cn

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill instructs the AI agent to "analyze the codebase" if run within a code directory. While this capability is presented as necessary for understanding the product to generate leads, it grants the agent broad access to local files. This represents a significant vulnerability risk (e.g., data exposure, potential for RCE if the agent's analysis involves executing untrusted code snippets) that could be exploited if the agent's execution environment is not securely sandboxed, or through subsequent prompt injection, even though the skill itself does not explicitly instruct malicious actions like exfiltration or persistence.