persona-mapping

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified.
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of @coldiq/mcp@latest via npx. This is a vendor-owned package from the author 'Cold-IQ' used to provide the necessary MCP connectivity for the skill's features.
  • [DATA_EXFILTRATION]: Mentions communication with the vendor's official API at api.coldiq.com for the purpose of people enrichment. This is a standard and expected behavior for a skill designed to enrich persona data.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests data from external API calls (mcp__coldiq__find_people). However, the skill does not possess exploitable capabilities such as arbitrary shell execution or file system writing, and there is no evidence of instructions attempting to bypass safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:37 PM
Security Audit — agent-trust-hub — persona-mapping