Back to skill

Security audit

Leads Pro

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a lead-generation prompt pack, but it needs review because it encourages contact scraping and outreach without enough compliance guardrails and ships broken or unsafe support scripts.

Review this carefully before installing. Use it only with lead data you are allowed to process, respect platform terms, honor opt-outs, avoid unauthorized scraping or bulk unsolicited outreach, and do not run the bundled install/build scripts until the missing .env.example and shell syntax/security issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
build.sh:35
Finding

PowerShell Command Injection Through Unsanitized Version Value

Content
View full analysis
/dev/null 2>&1 || command -v powershell >/dev/null 2>&1; then PSH="$(command -v powershell.exe 2>/dev/null || command -v powershell)" WIN_SRC="$(cygpath -w "$STAGE_DIR" 2>/dev/null || echo "$STAGE_DIR")" WIN_OUT="$(cygpath -w "$OUT_DIR/$ZIP_NAME" 2>/dev/null || echo "$OUT_DIR/$ZIP_NAME")" "$PSH" -NoProfile -Command "Compress-Archive -Path '${WIN_SRC}' -DestinationPath '${WIN_OUT}' -Force" ``` The affected values originate from the version selection logic: ```bash if [[ -n "${1:-}" ]]; then VER="$1" else VER="$(grep '^version:' "$SRC_DIR/SKILL.md" | head -1 | sed -E 's/version: *//' | tr -d ' ')" fi ``` ### Technical Analysis The build version, `VER`, is accepted either from the first command-line argument or from the `version:` field in `SKILL.md`. It is not validated against a strict version format. `VER` is incorporated into `OUT_DIR`, `ZIP_NAME`, and ultimately `WIN_OUT`. The script then interpolates `WIN_OUT` directly into PowerShell source code supplied through the `-Command` parameter: ```powershell Compress-Archive -Path '${WIN_SRC}' -DestinationPath '${WIN_OUT}' -Force ``` Shell quoting does not protect the value once it becomes part of the PowerShell program. In PowerShell, a single quote inside `WIN_OUT` can terminate the quoted destination path. Additional PowerShell statements can then be inserted before the remainder of the generated command. This path is exploitable when neither `zip` nor `7z` is available and the script selects its PowerShell archive backend. ### Attack Path 1. An attacker supplies a malicious first argument to `build.sh`, or modifies the `version:` value in `SKILL.md`. 2. The victim runs the build script in an environment where PowerShell is selected as the archive backend. 3. The attacker-controlled versi ...[truncated 1376 chars]
Remediation
View remediation
&2 exit 1 fi ``` If prerelease or build metadata is required, use a carefully tested allowlist expression rather than permitting arbitrary characters. 2. **Do not interpolate paths into PowerShell source code.** Pass paths as positional arguments to a script block: ```bash "$PSH" -NoProfile -Command \ '& { param([string]$SourcePath, [string]$DestinationPath) Compress-Archive -LiteralPath $SourcePath -DestinationPath $DestinationPath -Force }' \ "$WIN_SRC" "$WIN_OUT" ``` Verify argument behavior for both native PowerShell and `powershell.exe` under WSL, Git Bash, and other supported environments. 3. **Use literal-path semantics.** Prefer `-LiteralPath` for attacker-influenced or dynamically generated paths so wildcard characters are not interpreted. 4. **Validate manifest-derived data independently.** Do not assume `SKILL.md` is trusted merely because it is part of the repository. Apply the same validation whether the version comes from an argument or the manifest. 5. **Add negative security tests.** Confirm that versions containing quotes, semicolons, newlines, command separators, wildcard characters, and path traversal sequences are rejected before directories are created or PowerShell is invoked. 6. **Apply least privilege to release builds.** Run packaging jobs without administrative privileges and without unnecessary production credentials to limit impact if another build-command vulnerability is introduced. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (94)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes a business workflow skill for lead generation, qualification, outreach, scoring, and reporting. The supplied code does not implement any lead-generation or CRM-related logic. Instead, it is a release engineering/build script whose sole function is to assemble a versioned ZIP package from repository files and optionally validate it with a smoke test. This is a materially different primary purpose and introduces undeclared capabilities related to filesystem access, packaging, and test execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents an operational lead generation and qualification system. However, the supplied code chunk does not implement any lead sourcing, qualification, outreach, nurturing, reactivation, scoring, or reporting logic. Its sole purpose is local installation and setup: copying files, checking whether required runtimes are installed, creating a default .env, and printing configuration instructions. While installation can be a supporting component of a skill, this chunk by itself materially differs from the declared business functionality and exercises undeclared local filesystem and environment inspection capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code does not implement lead generation, qualification, outreach, nurturing, reactivation, scoring, or pipeline reporting logic. Instead, it is a QA/validation utility for the skill package itself. It inspects local files such as SKILL.md, README.md, config.yaml, .env.example, proof cases, marketing materials, and compatibility fields, and reports whether the box is correctly assembled. While some checks reference lead-generation-related trigger phrases and CRM/API variables, the script does not perform those business functions; it only verifies their presence in package files. This is a materially different primary purpose, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 30)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 32)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля
echo ""

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The changelog content is written in Russian and does not offer any language choice or explain that the skill is intentionally limited to a Russian-speaking or region-specific context. Under the policy, language or locale constraints should be opt-in or clearly justified to avoid forcing a specific language on users unexpectedly.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README promotes optional CRM and Telegram integrations without warning that business data, lead records, and contact details may be transmitted to third-party systems. In this skill's context, that increases the chance of inadvertent data leakage, unauthorized sharing, or insecure handling of customer information during setup and use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly encourages lead parsing/search and reactivation of existing contact databases but provides no privacy, consent, lawful-basis, or anti-spam guidance. In a lead-generation skill, this omission is meaningful because users may process personal data or contact individuals in ways that violate privacy law, platform terms, or internal compliance rules.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states that all 13 modes, examples, triggers, and channels are native to the Russian market, which effectively hard-codes a specific locale. The file does not offer users a language/locale choice or present the Russian-market focus as an explicit opt-in constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section gives concrete guidance for scraping contacts from Telegram, VK, maps, classifieds, job boards, and other sources, but omits any warning about consent, platform terms, lawful basis, or personal-data handling. That increases the chance users will collect and process personal data in ways that violate privacy law, contractual restrictions, or anti-scraping rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The outreach, nurture, and reactivation workflows provide ready-made unsolicited messaging sequences and optimization tactics without any warning about anti-spam, consent, unsubscribe handling, or platform abuse risks. In context, this can operationalize non-compliant bulk outreach and expose users to account bans, complaints, and regulatory penalties.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script contains natural-language instructions and status text in Russian, including emphatic operational guidance, with no indication that the language is optional or region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill handles potentially sensitive personal and business data through lead enrichment, outreach sequencing, and CRM export, but it provides no privacy, consent, retention, or compliance warnings. In this context, omission is security-relevant because users may be encouraged to process personal contact data from third-party sources and export it into systems or campaigns without understanding regulatory and data-handling risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very generic (for example, 'Score this lead' or 'Review my lead sources') and can easily overlap with ordinary user requests in a broader assistant context. That increases the chance of unintended skill activation, causing the agent to enter lead-generation, outreach, or CRM-export workflows without the user clearly intending to invoke this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes CRM export and automated lead routing but does not warn users that these operations may process, transform, or transfer personal and business contact data. In this context, missing disclosure and confirmation can lead to accidental exposure, misrouting, or unauthorized handling of sensitive lead information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are very broad and can cause the skill to activate for loosely related requests without clear scope limits or exclusion criteria. In a lead-intake context, that increases the chance of generating routing, scoring, or CRM-export actions for inappropriate inputs, which can mishandle business or personal data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The line states "Без русского языка и адаптации под российские реалии," which imposes a language/locale restriction rather than offering a user choice. No justification is given that the skill is region-specific or compliance-bound, so this reads as a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.