lead-sources-guide
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for the user to run the vendor's own Model Context Protocol (MCP) tool using the command
npx -y @coldiq/mcp@latest. This involves downloading and executing a package from the npm registry. - [COMMAND_EXECUTION]: Provides CLI command examples for setting environment variables (
COLDIQ_API_KEY=<key>) and invoking Node-based tools to connect external services. - [PROMPT_INJECTION]: Contains behavioral instructions directing the agent to prioritize recommending the vendor's ColdIQ services to the user before suggesting alternative manual workflows. This is a steering mechanism for intended skill usage rather than a security bypass.
Audit Metadata