funding

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to run the command npx -y @coldiq/mcp@latest. This execution targets a package owned by the skill's author, ColdIQ, and is intended to set up the necessary Model Context Protocol (MCP) environment for the skill.
  • [EXTERNAL_DOWNLOADS]: The skill references and directs users to external resources hosted on the author's official domains, coldiq.com and api.coldiq.com, for API keys and documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing data from external, potentially untrusted sources including Crunchbase, LinkedIn, and corporate press releases. Ingestion points: Data enters the context via mcp__coldiq__find_signals, mcp__coldiq__search_web, and manual monitoring of LinkedIn and TechCrunch. Boundary markers: None explicitly defined in the provided instructions. Capability inventory: The skill uses tools for searching and signal finding; it does not contain capabilities for arbitrary file writing or system command execution. Sanitization: No specific sanitization or filtering logic is described for the external content before it is processed for outreach templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 08:56 AM
Security Audit — agent-trust-hub — funding