LeadContact

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it should be reviewed because it enables lookup of people’s phone numbers and emails from LinkedIn profiles without clear consent or lawful-use guardrails.

Install only if you have a legitimate, compliant reason to enrich LinkedIn profiles and understand that profile URLs and returned contact data are handled by LeadContact. Keep the API token in the platform credential store, avoid bulk or automated lookups without a clear legal basis, and verify that outreach use complies with privacy, anti-spam, and platform rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill is explicitly designed to retrieve personal phone numbers and email addresses from LinkedIn profile URLs, but it provides no user-facing privacy notice, consent guidance, or restrictions on lawful use. This increases the risk of covert personal-data enrichment, scraping-adjacent usage, and downstream misuse for spam, stalking, or unauthorized profiling.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal