Back to skill

Security audit

Lead List Builder Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed lead-generation workflow that searches public business sites, enriches contact details, and writes results to Google Sheets, with privacy and dependency precautions users should still consider.

Before installing, use a dedicated virtual environment, pin or review dependencies, keep API keys and credentials.json out of source control, restrict the Google service account to the intended sheet, and confirm that collecting and using business contact data complies with applicable privacy and anti-spam rules.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/setup-guide.md:4
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: references/setup-guide.md:4-5
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install requests beautifulsoup4 lxml python-Wappalyzer python-whois \
            gspread google-auth aiohttp tldextract python-dotenv

Technical Analysis

The installation instructions fetch numerous third-party packages without exact version pins, package hashes, or a reviewed lockfile. Consequently, package resolution depends on mutable package-index state at installation time and can produce different dependency trees across installations.

Although the reviewed artifact contains no evidence that any named package is intentionally malicious, this installation pattern creates supply-chain exposure. A compromised package release, compromised transitive dependency, dependency-resolution change, or malicious replacement from an improperly configured package index could introduce attacker-controlled code.

Python packages and their build backends may execute code during installation. Installed dependencies also execute in the agent's runtime context, where they may access the process environment, local files available to the process, network resources, and data handled by the lead-generation workflow.

Attack Path

  1. An attacker compromises a listed package or one of its transitive dependencies, or causes dependency resolution to use an unsafe package source.
  2. The attacker publishes a malicious version that satisfies the unconstrained installation request.
  3. A user follows the setup guide and runs the documented pip install command.
  4. The malicious package executes code during package installation or when imported by the agent.
  5. That code accesses privileges available to the installing or runtime user. Depending on local configuration, this can include API keys stored in environment variables, the Google service-account JSON file, scrape ...[truncated 1024 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the unconstrained installation command with a reviewed dependency manifest that pins every direct and transitive dependency to an exact version.
  2. Generate and commit a lockfile using a suitable tool such as pip-tools, Poetry, or Pipenv.
  3. Require package hashes during installation, for example through a hash-locked requirements file and pip install --require-hashes.
  4. Install dependencies inside a dedicated virtual environment or isolated container rather than into a system-wide Python environment.
  5. Configure pip to use only explicitly trusted package indexes and prevent unintended fallback to untrusted sources.
  6. Scan dependencies with tools such as pip-audit or OSV-Scanner in continuous integration and before releases.
  7. Review dependency updates before regenerating the lockfile, rather than automatically accepting the newest available releases.
  8. Run the agent under a dedicated, non-privileged operating-system account and expose only the credentials required for the current operation.
  9. Restrict the Google service account to the intended sheet or minimum necessary resources, and rotate credentials if dependency compromise is suspected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 19)May include surrounding context.

DATAFORSEO_LOGIN=your_login # optional alternative to Serper DATAFORSEO_PASSWORD=your_password # optional GOOGLE_SHEET_NAME=Website Leads GOOGLE_CREDS_FILE=credentials.json REQUEST_DELAY=1.5 # seconds between site visits CONCURRENCY=5 # max parallel site fetches

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 28)May include surrounding context.

DATAFORSEO_LOGIN=your_login # optional alternative to Serper DATAFORSEO_PASSWORD=your_password # optional GOOGLE_SHEET_NAME=Website Leads GOOGLE_CREDS_FILE=credentials.json REQUEST_DELAY=1.5 # seconds between site visits CONCURRENCY=5 # max parallel site fetches

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 45)May include surrounding context.

md
## Hunter.io Setup (Optional)

1. Sign up at hunter.io (free: 25 searches/month)
2. Get API key from dashboard
3. Add to .env as HUNTER_API_KEY

## Google PageSpeed API Setup (Free)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 46)May include surrounding context.

md
1. Sign up at hunter.io (free: 25 searches/month)
2. Get API key from dashboard
3. Add to .env as HUNTER_API_KEY

## Google PageSpeed API Setup (Free)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 52)May include surrounding context.

md
1. Sign up at hunter.io (free: 25 searches/month)
2. Get API key from dashboard
3. Add to .env as HUNTER_API_KEY

## Google PageSpeed API Setup (Free)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 59)May include surrounding context.

md
1. Sign up at hunter.io (free: 25 searches/month)
2. Get API key from dashboard
3. Add to .env as HUNTER_API_KEY

## Google PageSpeed API Setup (Free)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 58)May include surrounding context.

md
## Serper.dev Setup

1. Sign up at serper.dev (2,500 free searches to start)
2. Copy API key from dashboard
3. Add to .env as SERPER_API_KEY

## Running the Agent

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to collect and enrich business contact data from webpages, WHOIS, and Hunter.io, but it does not warn the operator that personal or quasi-personal data may be gathered and processed. This creates a real privacy and compliance risk because users may trigger collection, enrichment, and downstream use of contact information without informed consent or awareness of applicable data-handling obligations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill writes discovered and enriched lead data to a Google Sheet but does not clearly warn that data will be transmitted to and stored in an external third-party service. This is dangerous because operators may unknowingly export potentially sensitive business contact records outside the local environment, increasing exposure, access-control, and accidental-sharing risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide explicitly instructs users to create a service account, store its JSON key locally, and grant that account Editor access to a Google Sheet that will hold discovered business and contact data, but it does not warn about the sensitivity of that data or the privilege level being granted. This increases the chance users will deploy the skill without understanding data-handling, sharing, and key-protection risks, which can lead to unauthorized access or unintended disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.