source-companies
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the installation of the
@coldiq/mcppackage via npm. As the package is owned by the skill author 'cold-iq', this is categorized as a standard vendor resource. - [COMMAND_EXECUTION]: The instructions include a setup command for the user to connect the ColdIQ MCP (
npx -y @coldiq/mcp@latest). This is a documented installation step for the author's own integration. - [SAFE]: The skill uses placeholders for API keys (
<key>) and directs users to the official vendor domainapi.coldiq.comfor service enrichment, following best practices for secret management and resource sourcing.
Audit Metadata