Back to skill

Security audit

Lead Gen Research

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed lead-research skill that uses public prospect information and templates, with a privacy-compliance documentation gap users should handle carefully.

Install only if you are comfortable using it for lawful B2B prospect research. Provide only authorized company or professional contact data, avoid sensitive personal data, respect LinkedIn/X and CRM terms, and set your own retention, opt-out, and deletion practices for any lead lists you process.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README promotes bulk prospect research, social profiling, and CSV/CRM processing but provides no warning or guidance about handling personal data, lawful basis, retention, consent expectations, or platform terms. In a lead-generation context, this omission can encourage users to ingest and enrich personal/professional data at scale without considering privacy obligations, increasing the likelihood of misuse, noncompliance, or unsafe downstream sharing.

Static analysis

No suspicious patterns detected.