Back to skill

Security audit

company-enrichment

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Superagnt company-enrichment connector that calls an external API and can return domain emails, with no local code execution or persistence found.

Install only if you are comfortable sending company/domain research inputs and any bulk account lists to Superagnt. Use domain-email results only for authorized business purposes, keep the API key scoped and protected, and avoid enabling extra MCP tool families unless you intentionally need them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest description says the skill provides company enrichment and account research, but it does not disclose that it can enumerate email addresses for a domain. That omission can mislead users or calling agents about the sensitivity of the capability and cause them to invoke a more privacy-impacting action than expected.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill introduces a '/companies/domain-emails' endpoint under a general company-enrichment skill without clearly justifying why enumerating email addresses is necessary for the stated purpose. This increases the risk of misuse for contact harvesting or recon because the sensitive capability is packaged as routine firmographic enrichment.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends company/domain queries and may return email-address data from an external third-party API, but the description does not prominently warn users that their inputs and retrieved data leave the local environment. This can create privacy, compliance, and trust issues, especially if users supply sensitive prospecting lists or internal research targets.

External Transmission

Medium
Category
Data Exfiltration
Content
One call proves the key, the credit balance, and this source end to end:

```bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'
```
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
One call proves the key, the credit balance, and this source end to end:

```bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'
```
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
One call proves the key, the credit balance, and this source end to end:

```bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'
```
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
One call proves the key, the credit balance, and this source end to end:

```bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'
```
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Example

```bash
curl -X POST 'https://api.superagnt.com/v1/data/agnt/companies/enrich' \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{"...": "see tool schemas below"}'
Confidence
60% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Static analysis

No suspicious patterns detected.