atl-messaging

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the official Cold-IQ Model Context Protocol (MCP) package from the npm registry.
  • [REMOTE_CODE_EXECUTION]: The npx command downloads and executes the @coldiq/mcp package at runtime.
  • [COMMAND_EXECUTION]: Provides an initialization command for the Cold-IQ MCP server (npx -y @coldiq/mcp@latest).
  • [PROMPT_INJECTION]: Evaluates external data from enrichment tools to draft strategic emails, establishing an indirect prompt injection surface. 1. Ingestion points: Data from mcp__coldiq__enrich_person and mcp__coldiq__find_signals tools. 2. Boundary markers: None present. 3. Capability inventory: Drafting email content; no direct system or network capabilities in the skill scripts. 4. Sanitization: None specified for external tool outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:37 PM
Security Audit — agent-trust-hub — atl-messaging