signal-sourcer

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and execute the ColdIQ MCP package (@coldiq/mcp@latest) from the public NPM registry to enable enhanced signal detection capabilities.
  • [COMMAND_EXECUTION]: Setup instructions involve the execution of shell commands (using npx) to initialize the agent's connection to external signal providers and set local environment variables for API authentication.
  • [SAFE]: Comprehensive analysis of the 137 buying triggers, 11 GTM plays, and scoring frameworks found no evidence of malicious behavior, data exfiltration, or prompt injection. All external tool references and command instructions are consistent with the skill's legitimate purpose in sales operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:37 PM
Security Audit — agent-trust-hub — signal-sourcer