Back to skill

Security audit

Prospector

Security checks for vulnerabilities and agentic risk

Overview

The skill does lead prospecting as advertised, but its setup instructions handle API keys unsafely and can modify shell startup files in ways that create real local execution and persistence risk.

Review this skill before installing. Only run setup with API keys you generated yourself, avoid writing keys into shell profiles, prefer environment variables or a proper secret manager, and treat exported CSV lead data as sensitive. Before using Attio sync, confirm you are allowed to send and retain those contacts in that CRM. The package should be fixed to pass secrets as data, quote shell exports safely, pin dependencies, and neutralize CSV formulas.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
commands/setup.md:202
Finding

Persistent Shell Command Injection Through API Key Storage

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
commands/setup.md:75
Finding

Arbitrary Python Code Injection During API Key Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/prospector.py:369
Finding

Spreadsheet Formula Injection in Exported Lead CSV Files

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:13
Finding

Unpinned Global Installation of a Third-Party Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (25)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 39)May include surrounding context.

md
2. Ask for your Apollo API key and validate it
3. Optionally ask for your Attio API key
4. Optionally set environment variables in your shell profile
5. Save keys securely to `~/.config/prospector/config.json` (chmod 600)

### Finding Leads

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 139)May include surrounding context.

md
2. Ask for your Apollo API key and validate it
3. Optionally ask for your Attio API key
4. Optionally set environment variables in your shell profile
5. Save keys securely to `~/.config/prospector/config.json` (chmod 600)

### Finding Leads

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/prospector.py (reported line 52)May include surrounding context.

python
2. Ask for your Apollo API key and validate it
3. Optionally ask for your Attio API key
4. Optionally set environment variables in your shell profile
5. Save keys securely to `~/.config/prospector/config.json` (chmod 600)

### Finding Leads

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly describes exporting personal contact data, including names, emails, locations, and LinkedIn URLs, to a CSV on the user's Desktop without any privacy, retention, or secure-handling guidance. That creates a real data-protection risk because Desktop files are easily exposed through backups, screen sharing, local multi-user access, or accidental onward sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that leads can be synced to Attio CRM, including company and people records, but does not warn that personal contact data will be transmitted to a third-party service. This is a genuine privacy/security concern because users may unknowingly send regulated or sensitive business-contact data to another processor without understanding the disclosure, retention, and access implications.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

Creating persistent CRM people/company records from prospecting data introduces a real session/data persistence risk because imported personal data may remain in the CRM indefinitely and become accessible to broader teams or downstream integrations. In this skill context, the danger is increased because the workflow is expressly designed to collect and enrich contact records at scale, making over-retention and secondary use more likely.

Content

Scanner excerpt · README.md (reported line 77)May include surrounding context.

md
If you configured Attio during setup, you'll be asked after each search if you want to sync the leads. This will:
- Create/update Companies in Attio (matched by domain to avoid duplicates)
- Create People linked to their companies

## CLI Usage

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 108)May include surrounding context.

}

text

The file is automatically set to `chmod 600` (owner read/write only).

### Environment Variables (Recommended)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · commands/setup.md (reported line 260)May include surrounding context.

}

text

The file is automatically set to `chmod 600` (owner read/write only).

### Environment Variables (Recommended)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell commands, reads environment variables, writes configuration and CSV files, and sends data to external services, but it declares no explicit tool scope or permissions. That makes the skill's operational reach opaque to the user and platform, increasing the risk of over-privileged execution or unexpected data access if the skill is run in an agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends user-provided ICP criteria and retrieved prospect/contact data to third-party services Exa, Apollo, and optionally Attio, but the description lacks an explicit privacy notice. This is dangerous because users may not understand that their search criteria and resulting lead data are being transmitted off-platform to external vendors, creating privacy, compliance, and data-handling risks.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · commands/setup.md (reported line 6)May include surrounding context.

md
allowed-tools:
  - Bash
  - AskUserQuestion
  - Write
  - Read
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup flow asks the user to paste API keys and then sends those secrets to third-party endpoints for validation, but it does not explicitly warn the user that their credentials will be transmitted over the network. Although validating a key against the vendor API is a legitimate pattern, the lack of clear disclosure reduces informed consent and increases the chance of unexpected secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill offers to append plaintext API keys directly into shell startup files, which creates persistent local secret storage in locations that may be broadly read by local tools, backup systems, or accidentally shared dotfiles. The issue is compounded by the absence of an explicit warning that secrets will be written into startup scripts in plaintext.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill saves API keys in plaintext to ~/.config/prospector/config.json and only later mentions that keys are stored there, rather than warning beforehand that credentials will be written to disk. Even with chmod 600, plaintext storage can still expose secrets to local compromise, backups, endpoint tooling, or accidental exfiltration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · commands/setup.md (reported line 86)May include surrounding context.

md
try:
        with httpx.Client(timeout=30) as client:
            resp = client.post(
                "https://api.exa.ai/search",
                headers={"x-api-key": api_key, "Content-Type": "application/json"},
                json={"query": "test", "numResults": 1},
            )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prospector.py (reported line 116)May include surrounding context.

python
try:
        with httpx.Client(timeout=30) as client:
            resp = client.post(
                "https://api.exa.ai/search",
                headers={"x-api-key": api_key, "Content-Type": "application/json"},
                json={"query": "test", "numResults": 1},
            )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prospector.py (reported line 167)May include surrounding context.

python
try:
        with httpx.Client(timeout=30) as client:
            resp = client.post(
                "https://api.exa.ai/search",
                headers={"x-api-key": api_key, "Content-Type": "application/json"},
                json={"query": "test", "numResults": 1},
            )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · commands/setup.md (reported line 119)May include surrounding context.

md
try:
        with httpx.Client(timeout=30) as client:
            resp = client.post(
                "https://api.apollo.io/api/v1/mixed_people/search",
                headers={"x-api-key": api_key, "Content-Type": "application/json"},
                json={"per_page": 1},
            )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prospector.py (reported line 130)May include surrounding context.

python
try:
        with httpx.Client(timeout=30) as client:
            resp = client.post(
                "https://api.apollo.io/api/v1/mixed_people/search",
                headers={"x-api-key": api_key, "Content-Type": "application/json"},
                json={"per_page": 1},
            )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prospector.py (reported line 190)May include surrounding context.

python
try:
        with httpx.Client(timeout=30) as client:
            resp = client.post(
                "https://api.apollo.io/api/v1/mixed_people/search",
                headers={"x-api-key": api_key, "Content-Type": "application/json"},
                json={"per_page": 1},
            )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · commands/setup.md (reported line 162)May include surrounding context.

md
try:
        with httpx.Client(timeout=30) as client:
            resp = client.get(
                "https://api.attio.com/v2/self",
                headers={"Authorization": f"Bearer {api_key}"},
            )
            return resp.status_code == 200

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prospector.py (reported line 144)May include surrounding context.

python
try:
        with httpx.Client(timeout=30) as client:
            resp = client.get(
                "https://api.attio.com/v2/self",
                headers={"Authorization": f"Bearer {api_key}"},
            )
            return resp.status_code == 200

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prospector.py (reported line 222)May include surrounding context.

python
try:
        with httpx.Client(timeout=30) as client:
            resp = client.get(
                "https://api.attio.com/v2/self",
                headers={"Authorization": f"Bearer {api_key}"},
            )
            return resp.status_code == 200

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prospector.py (reported line 261)May include surrounding context.

python
try:
        with httpx.Client(timeout=30) as client:
            resp = client.get(
                "https://api.attio.com/v2/self",
                headers={"Authorization": f"Bearer {api_key}"},
            )
            return resp.status_code == 200

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow states that lead data is exported to CSV on the user's Desktop, but the user-facing description does not clearly warn about that local file write. This can cause unintended storage of potentially sensitive prospecting data in an exposed or synced location, especially on shared machines or systems with cloud-desktop sync enabled.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.