cold-call-scripts
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The s kill recommends using 'n p x
- y @coldi q / m c p @ l a test' to set u p the M CP connection. This downloads and executes a package from the n pm reg i stry. T he package belongs to the skill aut ho r's orga n izat i o n ('@col diq'), representing standar d ve ndo r functionali t y .
- [P R OMPT_INJEC TION]: The s k ill is desi gned to use MCP tools like 'm cp__c o l di q__enri ch_person' and 'm cp__coldiq__fetch_page_content' to gather ex ter na l da ta f or script populat i o n. Thi s cre ates a potent i al sur face for indirect prompt injection if the sourced dat a con t ains maliciou s instr uctions. * Inge s ti o n po i nt s : D ata returne d by enrichment tools i n SKIL L . m d. * Boun da r y ma r k ers : N o e xpli c i t del i m i te rs or instruc tions are pro vi ded to the a ge n t t o ignore em be d de d command s within the f e tc h e d da t a . * Ca p abi l i ty i n v en t o r y : M CP tools are us ed for dat a retrie val. * Sanitiza t i on: No spec i f i c sanitiza ti on steps are mentioned.
Audit Metadata