Back to skill

Security audit

Lead Gen Website Pipeline

Security checks across malware telemetry and agentic risk

Overview

The skill is transparent about building a sales automation pipeline, but it would let external code use sensitive accounts to deploy sites and send recurring cold emails with limited safety guidance.

Install only after reviewing the external repository and its dependencies. Use test accounts first, least-privilege API keys, tight rate limits, dry runs, and manual approval for every generated website and email. Add unsubscribe/suppression handling and confirm cold-email compliance for the jurisdictions you contact before enabling cron or continuous polling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly automates cold outreach and multi-step follow-up emails to real businesses, but the description does not foreground the compliance, consent, anti-spam, and reputational risks of doing so. In this context, omission is meaningful because the workflow is designed for unattended execution and scaled outbound contact, which can lead users to deploy it without understanding legal or policy constraints.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill requests multiple high-value credentials and service-account access spanning Google APIs, Vercel, email delivery, and Sheets, yet provides no security guidance on storage, scoping, rotation, or least-privilege setup. Because this pipeline can deploy content, access lead data, and send outbound emails, mishandled credentials could enable unauthorized data access, spam sending, account abuse, or infrastructure misuse.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The manifest explicitly advertises a fully automated cold outreach and email drip capability but provides no warning, gating, or consent/privacy guidance for handling recipient data and initiating external communications. In this context, the omission is security-relevant because the skill is designed to collect business/contact information and send unsolicited outbound emails at scale, which increases the risk of privacy violations, spam abuse, and reputational or compliance harm.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The document instructs users to create a long-lived GCP service account key and store the JSON credential on disk without any warning about secret handling, rotation, file permissions, or safer alternatives. In a pipeline that automates lead collection and outreach, compromise of this key could grant persistent unauthorized access to the linked Google Sheet and potentially other resources scoped to the service account.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.