devils-advocate

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and run '@coldiq/mcp@latest' using npx. This involves external code retrieval from the npm registry. Since the package is within the cold-iq vendor namespace, this represents legitimate integration with the author's services.
  • [COMMAND_EXECUTION]: The documentation includes a shell command for setting environment variables and launching the MCP tool.
  • [PROMPT_INJECTION]: The skill ingests untrusted user data (prompts and strategies) which provides a surface for indirect prompt injection. Ingestion points: User-provided content passed for critique in SKILL.md. Boundary markers: None explicitly defined to isolate input from instructions. Capability inventory: Network-based company and contact search via ColdIQ tools mentioned in SKILL.md. Sanitization: No specific sanitization or filtering of input is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:01 PM
Security Audit — agent-trust-hub — devils-advocate