Data Enricher

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: enrich lead records with contact emails and prepare them for Notion.

Install only if you are comfortable sending lead domains to Hunter.io, using a scoped Hunter.io API key, granting Notion access only to the intended lead pipeline, and retaining enriched lead data in the workspace until you delete it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs saving enriched lead data to a workspace JSON file but does not warn the user that business/contact data will be written to local storage. This creates a privacy and data-governance risk because users may unknowingly persist potentially sensitive lead information in a shared or insecure workspace.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends domain data to the external Hunter.io API without clearly warning the user that lead-related information will be transmitted to a third party. Even if the data is only domains, this can expose business intelligence, prospecting targets, or workflow contents to an external service without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal