multi-signal

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for users to install the @coldiq/mcp package from the NPM registry using npx. This is a legitimate vendor resource provided by Cold-IQ for integrating their signal-sourcing capabilities.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources, such as intent signals and web search results, which introduces a surface for indirect prompt injection.
  • Ingestion points: SKILL.md (instructions for calling mcp__coldiq__find_signals and mcp__coldiq__search_web tools).
  • Boundary markers: None explicitly defined to separate untrusted tool outputs from instructions.
  • Capability inventory: Data analysis, lead scoring calculation, and response generation; no high-privilege operations like file system writes or arbitrary command execution are granted to the agent based on the ingested data.
  • Sanitization: No specific filtering or sanitization protocols for external content are mentioned in the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:37 PM
Security Audit — agent-trust-hub — multi-signal