Back to skill

Security audit

Trade Show Contact Finder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Lensmor contact-search helper that uses an API key to look up company contacts and explicitly avoids paid email or phone unlocks.

Install only if you intend to use Lensmor for company contact lookup and are comfortable providing a Lensmor API key. Review results before using them for outreach, especially any already-unlocked email fields returned by the API.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description packs many broad multilingual trigger phrases such as generic requests to find contacts or buyers. This can cause the skill to activate for ordinary user queries more often than intended, increasing the chance that sensitive contact-enrichment behavior is invoked without clear user intent or proper workflow context.

Static analysis

No suspicious patterns detected.