buying-signals-6

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the @coldiq/mcp package available via npm. This is a vendor-specific resource provided by the author to enable signal detection capabilities.
  • [COMMAND_EXECUTION]: The documentation provides a command (npx -y @coldiq/mcp@latest) to initialize the vendor's MCP tool. This is a standard procedure for integrating the Cold-IQ service into the agent environment.
  • [DATA_EXFILTRATION]: The skill interacts with api.coldiq.com and various mcp__coldiq__* tools. These are official vendor endpoints and tools used to fetch market intelligence and contact data as part of the skill's primary function.
  • [PROMPT_INJECTION]: The skill involves fetching data from external sources such as press releases and job postings via mcp__coldiq__search_web. While this presents an indirect prompt injection surface, it is a standard requirement for the tool's research functionality and does not exhibit malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:37 PM
Security Audit — agent-trust-hub — buying-signals-6