Back to skill

Security audit

Lead Gen

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent B2B lead-generation skill, but it needs Review because it guides contact enrichment and email guessing without enough privacy, consent, or anti-spam boundaries.

Install only for legitimate, authorized B2B prospecting. Before use, define a clear ICP and outreach purpose, prefer compliant opt-in or official business contact sources, label guessed emails as unverified, avoid mining personal profiles or developer artifacts for outreach without a lawful basis, honor opt-outs, and follow CAN-SPAM, GDPR, platform terms, and local privacy rules.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is very broad and includes common sales- and research-related phrases such as "find leads," "who should I target," and "find emails," which could cause the skill to activate in contexts the user did not intend. Misrouting requests into a prospecting workflow can lead to unnecessary data collection, privacy-sensitive enrichment, or use of external searches when a narrower skill would have been more appropriate.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to enrich personal contact data and infer email addresses from company patterns, but provides no privacy, consent, retention, or acceptable-use guardrails. In a lead-generation context, this increases the risk of collecting or generating personal data in ways that may violate platform policy, privacy expectations, or anti-spam and data-protection requirements.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The playbook gives actionable instructions for deriving and validating likely personal work email addresses without any guardrails around consent, lawful basis, data minimization, or anti-spam compliance. In a lead-generation skill, this materially increases the chance of privacy-invasive contact harvesting and misuse of personal data at scale, even if the content appears framed as standard sales prospecting.

Static analysis

No suspicious patterns detected.