devils-advocate
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and run '@coldiq/mcp@latest' using npx. This involves external code retrieval from the npm registry. Since the package is within the cold-iq vendor namespace, this represents legitimate integration with the author's services.
- [COMMAND_EXECUTION]: The documentation includes a shell command for setting environment variables and launching the MCP tool.
- [PROMPT_INJECTION]: The skill ingests untrusted user data (prompts and strategies) which provides a surface for indirect prompt injection. Ingestion points: User-provided content passed for critique in SKILL.md. Boundary markers: None explicitly defined to isolate input from instructions. Capability inventory: Network-based company and contact search via ColdIQ tools mentioned in SKILL.md. Sanitization: No specific sanitization or filtering of input is mentioned.
Audit Metadata