Back to skill

Security audit

LeadContact

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward LeadContact API guide for looking up contact details from LinkedIn URLs, but users should treat it as privacy-sensitive.

Install only if you intend to use LeadContact for contact enrichment. Before running lookups, understand that LinkedIn profile URLs will be sent to LeadContact and the response may include personal phone numbers or email addresses; use it only where you have authorization and a lawful basis, and keep the API token and returned contact data protected.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly sends LinkedIn profile URLs to a third-party enrichment service and returns personal phone numbers and email addresses, but it does not warn users that personal/profile data will be transmitted off-platform and that additional personal data may be retrieved. This creates a privacy and consent risk, especially because users may not realize the lookup involves external processing and sensitive contact enrichment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The JavaScript example sends a LinkedIn profile URL and API token to an external API endpoint. Although this is expected for the integration, it is dangerous if used without transparency because it shares profile-identifying data with a third party and enables retrieval of sensitive contact details that may be used for unsolicited outreach or deanonymization.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

Example 1: Find Phone Number

javascript
const response = await fetch('https://leadcontact.ai/api/v1/phone', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer YOUR_TOKEN',

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example performs an outbound POST request to LeadContact with a LinkedIn profile URL, transmitting user-supplied profile data to a third party and retrieving personal contact information. In this skill's context, the transmission is the intended functionality, but it is still security-relevant because it exposes personal data to an external service and can facilitate privacy-invasive contact discovery.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
"profileUrl": "https://www.linkedin.com/in/johndoe/"
}

response = requests.post(url, json=data, headers=headers)
result = response.json()
email = result['data']['sources'][0]['email']
print(f"Found email: {email}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The cURL examples demonstrate direct transmission of LinkedIn profile URLs to a third-party contact-enrichment service. This is not malware-like behavior, but it is a real privacy/security concern in context because it operationalizes bulk external enrichment of personal contact data without any built-in consent, warning, or minimization controls.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

print(f"Found email: {email}")

text

### Example 3: cURL

```bash
# Find phone number

Static analysis

No suspicious patterns detected.