source-companies

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the @coldiq/mcp package via npm. As the package is owned by the skill author 'cold-iq', this is categorized as a standard vendor resource.
  • [COMMAND_EXECUTION]: The instructions include a setup command for the user to connect the ColdIQ MCP (npx -y @coldiq/mcp@latest). This is a documented installation step for the author's own integration.
  • [SAFE]: The skill uses placeholders for API keys (<key>) and directs users to the official vendor domain api.coldiq.com for service enrichment, following best practices for secret management and resource sourcing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 08:55 AM
Security Audit — agent-trust-hub — source-companies