Back to skill

Security audit

Lead Generation

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent lead-generation skill that uses Xpoz and local files for its stated prospecting workflow, with privacy and provenance notes users should review.

Install only if you trust Xpoz, mcporter, and the xpoz-setup OAuth flow. Avoid putting confidential product or customer details into generated search queries, periodically review or delete data/lead-generation files, and edit outreach drafts so they are accurate and compliant before sending.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs storing discovered leads in local files, including identifiers such as platform, author, post ID, and potentially quoted social content, without any explicit notice about data retention, access controls, or minimization. Because this skill is specifically designed to collect prospect information from live social conversations, silent local persistence increases privacy and compliance risk if the workstation is shared, compromised, or the data is retained longer than necessary.

Static analysis

No suspicious patterns detected.