job-changes
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute the
@coldiq/mcppackage from the NPM registry usingnpx. This is a vendor-owned resource required to enable the skill's core search and tracking functionality. - [COMMAND_EXECUTION]: Includes a shell command (
npx -y @coldiq/mcp@latest) to initialize the Cold-IQ MCP server, which is necessary for the agent to access specialized B2B intelligence tools. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to process untrusted data from external LinkedIn profiles.
- Ingestion points: LinkedIn URLs provided in the user's workspace or manual inputs (SKILL.md).
- Boundary markers: None specified in the instructions.
- Capability inventory: The skill utilizes network-enabled MCP tools (
mcp__coldiq__search_jobs,mcp__coldiq__find_signals) to query external databases (SKILL.md). - Sanitization: No specific validation or sanitization logic is described for the content retrieved from LinkedIn URLs.
Audit Metadata