Back to skill

Security audit

Enterprise Contact Information Query - 企业联系方式查询

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward company contact lookup tool that uses a disclosed JisuAPI key and endpoint.

Install this only if you are comfortable sending company names or registration identifiers to JisuAPI using your own API key, which may consume quota or incur charges. Treat returned names, phone numbers, emails, and roles as privacy-sensitive business contact data and use them only where appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill metadata declares required environment access via JISU_API_KEY and the documented usage clearly invokes a third-party API, but the skill does not explicitly surface corresponding permission implications to users. This creates a real transparency and governance issue because enterprise identifiers and queries may be transmitted off-platform to an external provider without clear consent or review boundaries.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger phrase 'or similar enterprise contact information questions' is broad enough to cause over-invocation outside a narrowly defined use case. In context, that matters because activation can lead to third-party lookups and disclosure of contact data even when the user's intent is ambiguous or the request concerns sensitive individuals rather than public corporate records.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation states that enterprise contact data will be queried and returned, but it does not clearly warn that the request is sent to a third-party service or explain privacy/compliance implications. This is significant because company names, registration numbers, and related lookup targets may be sensitive in business contexts, and users may not expect external transmission or downstream retention by the provider.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.