Back to skill

Security audit

Gov Permit Scraper

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed lead-generation scraper, but it can automatically email scraped and search-enriched contacts without enough review, limits, or enforcement safeguards.

Review this skill carefully before installing or running it. Use dry-run first, do not provide a Resend API key until recipients are reviewed, confirm that each data source and outreach use is lawful for your jurisdiction, and fix the missing date filtering, suppression, unsubscribe, rate limiting, and CSV escaping before live campaigns.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/permit-pipeline.js:157
Finding

Spreadsheet Formula Injection in Generated CSV Files

Content
View full analysis
`"${l.business}","${l.permitType}","${l.address}","${l.city}","${l.email || ''}","${l.status}","${l.date}"` ).join('\n'); fs.writeFileSync(filename, header + rows); console.log(`\n💾 Saved ${leads.length} leads to ${filename}`); } ``` ### Technical Analysis The application exports remotely sourced permit information and search-derived email addresses directly into CSV cells without neutralizing spreadsheet formula prefixes. Values beginning with `=`, `+`, `-`, or `@` may be interpreted as formulas when the resulting file is opened in spreadsheet software. Wrapping a value in double quotes does not prevent formula evaluation. The implementation also fails to escape embedded double quotes, carriage returns, and line feeds, allowing malicious data to alter the logical structure of the CSV file. The affected fields include: - Business name - Permit type - Address - City - Email address - Permit date These values originate wholly or partly from external government pages and Brave Search results and therefore must not be treated as trusted spreadsheet content. ### Attack Path 1. An attacker causes a formula-like string to appear in a permit record or another externally retrieved field, such as a business name beginning with `=HYPERLINK(...)`. 2. The pipeline downloads and parses the malicious value. 3. `saveToCSV` inserts the value into the generated CSV without formula neutralization or correct field escaping. 4. An operator opens the CSV file in spreadsheet software. 5. The spreadsheet interprets the attacker-controlled value as a formula. 6. Depending on the spreadsheet product and its se ...[truncated 716 chars]
Remediation
View remediation
[ lead.business, lead.permitType, lead.address, lead.city, lead.email || '', lead.status, lead.date ].map(csvCell).join(',')).join('\n'); fs.writeFileSync(filename, header + rows); } ``` ]]>

other

Warning
Location
scripts/permit-pipeline.js:177
Finding

Automated Outreach Lacks Date Enforcement and Abuse-Prevention Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes an automated pipeline that scrapes government records, enriches identities with emails, stores results, and sends outreach, but it does not include a clear warning about privacy, consent, compliance, rate-limiting, or external side effects. Because it directly affects third-party systems and personal/business contact data, the omission can lead users to run high-impact actions without understanding legal, privacy, and reputational consequences.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
node scripts/permit-pipeline.js --source tabc --since 2026-03-01

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
node scripts/permit-pipeline.js --source tabc --since 2026-03-01

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
node scripts/permit-pipeline.js --source tabc --since 2026-03-01

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill references environment-based secrets and operational capabilities like API keys for search and email services, but it does not declare any explicit tool scope or permissions boundary. That makes the skill's external reach and secret usage implicit rather than auditable, increasing the risk of unauthorized data access, unintended email sending, or misuse of available credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description uses broad prospecting and sales-oriented trigger phrases that can cause the skill to be invoked in many loosely related contexts without clearly surfacing that it performs scraping, enrichment, and automated outreach. Overbroad invocation raises the chance of accidental activation for sensitive workflows involving personal or business contact data and external messaging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file explicitly instructs users to enrich permit-holder records with email addresses and send automated outreach within 48 hours, but provides no warning or controls around privacy, anti-spam, consent, or jurisdiction-specific compliance requirements. In the context of a lead-generation skill, this omission can facilitate unlawful or abusive bulk contact practices and increases the likelihood that operators will misuse scraped public records for unsolicited outreach.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The enrichment step transmits business names and cities to Brave Search to discover contact emails, sharing collected lead data with a third-party service. While outbound API use is not inherently unsafe, in this context it expands data exposure and facilitates targeted harvesting of contact information for unsolicited outreach, which materially raises privacy and compliance concerns.

Content

Scanner excerpt · scripts/permit-pipeline.js (reported line 115)May include surrounding context.

js
if (!BRAVE_KEY) return null;
  try {
    const query = encodeURIComponent(`${business} ${city} email contact`);
    const url = `https://api.search.brave.com/res/v1/web/search?q=${query}&count=3`;
    const res = await httpGet(url, { 'X-Subscription-Token': BRAVE_KEY, 'Accept': 'application/json' });
    const json = JSON.parse(res.data);
    // Look for emails in descriptions and URLs

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The script sends generated outreach emails and recipient addresses to Resend automatically, causing immediate external transmission of campaign content to scraped contacts. In this skill’s lead-scraping and auto-outreach context, that behavior is more dangerous than generic email API usage because it turns harvested data into active unsolicited contact without review or compliance controls.

Content

Scanner excerpt · scripts/permit-pipeline.js (reported line 146)May include surrounding context.

js
if (!RESEND_KEY) { console.log('  ⚠️ No RESEND_API_KEY — skipping'); return false; }

  const res = await httpPost('https://api.resend.com/emails', {
    from: `${config.fromName || 'Outreach'} <${config.fromEmail || 'hello@yourdomain.com'}>`,
    to: [to],
    subject: template.subject.replace('{business_name}', businessName),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script stores scraped permit details and discovered email addresses to a local CSV without notice, minimization, or access controls. In a lead-generation skill that aggregates business identity and contact data, silent persistence increases the chance of unauthorized reuse, leakage, or accumulation of regulated/personal contact information on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The pipeline automatically sends emails to scraped and heuristically enriched contacts as part of normal execution, with no explicit confirmation gate, approval workflow, recipient review, or consent validation beyond an optional dry-run flag. In this skill’s context, that behavior directly operationalizes unsolicited outreach to third-party contacts gathered from public records and search results, creating meaningful abuse, privacy, spam, and compliance risk if run unintentionally or at scale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.