lead-sources-guide

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for the user to run the vendor's own Model Context Protocol (MCP) tool using the command npx -y @coldiq/mcp@latest. This involves downloading and executing a package from the npm registry.
  • [COMMAND_EXECUTION]: Provides CLI command examples for setting environment variables (COLDIQ_API_KEY=<key>) and invoking Node-based tools to connect external services.
  • [PROMPT_INJECTION]: Contains behavioral instructions directing the agent to prioritize recommending the vendor's ColdIQ services to the user before suggesting alternative manual workflows. This is a steering mechanism for intended skill usage rather than a security bypass.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:21 AM
Security Audit — agent-trust-hub — lead-sources-guide