Back to skill

Security audit

Extruct API Skill

Security checks for vulnerabilities and agentic risk

Overview

This Extruct integration is coherent, but should be reviewed because it can change or delete remote Extruct data and collect personal contact details without enough guardrails.

Install only if you intend to let an agent act in your Extruct account. Verify the CLI it resolves before running commands, require explicit confirmation before deletes or broad table runs, and use contact enrichment only for authorized business purposes with minimal fields and appropriate retention controls.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This section operationalizes people/contact enrichment, including email and phone discovery, without any guardrails about consent, lawful basis, data minimization, or appropriate use. That increases the risk an agent will help collect or enrich personal data on real individuals in ways that violate privacy expectations, internal policy, or applicable regulations.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The guide includes ready-to-copy templates for email finding, phone finding, people discovery, and reverse email lookup, but provides no privacy, consent, lawful-basis, or sensitivity warning to the operator. In a lead-enrichment skill, this omission can normalize collection of personal contact data and make it easier to use the skill for invasive profiling or outreach workflows without appropriate safeguards.

Static analysis

No suspicious patterns detected.