email-infra

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to run npx -y @coldiq/mcp@latest. This command downloads and executes the latest version of the ColdIQ MCP package from the npm registry. This is a vendor-owned resource used for the skill's primary functionality of email verification.
  • [DATA_EXFILTRATION]: The skill mentions the use of https://api.coldiq.com and mcp__coldiq__verify_email tools. These are identified as legitimate vendor-owned resources for the 'Cold-IQ' author and are used for the stated purpose of email infrastructure verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:37 PM
Security Audit — agent-trust-hub — email-infra