Back to skill

Security audit

lead-research-assistant

Security checks for vulnerabilities and agentic risk

Overview

This lead-research skill is coherent, but it should be reviewed because it encourages broad source-code analysis without warning users about sensitive repository contents.

Before installing, use this only on repositories you are comfortable having analyzed for sales research. Exclude secrets, credentials, private customer data, and sensitive source files, and make sure any contact or LinkedIn information is collected and used in compliance with privacy, platform, CRM, and outreach rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill says it will gather information about decision-makers and company context, and later requests LinkedIn URLs and contact targeting, without any privacy guidance, source restrictions, or caution about personal data handling. While common in sales workflows, this still poses a genuine privacy/compliance risk because it encourages collection and use of identifiable professional contact data without explaining lawful sourcing, minimization, or appropriate use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs users to run it from a product source code directory and to let it analyze the repository to understand the product, but it provides no warning that repository contents may include secrets, proprietary code, credentials, or other sensitive data. This creates a real privacy and data-exposure risk because users may grant broad access without informed consent, and the skill normalizes codebase inspection as part of routine lead generation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.