email-lead-extractor
Fail
Audited by Snyk on May 17, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt includes proxy credentials embedded in configuration examples (HTTP_PROXY and browser proxy with USER:PASS) which instruct the agent to place username/password verbatim into commands/configs, creating an exfiltration risk if real secrets are used.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to crawl and scrape open/public third-party sources — company websites, Google Search/Google Maps results, and directory sites like Yellow Pages and Yelp — and to parse those pages to extract emails and drive outreach decisions, so untrusted user-generated or public web content can directly influence agent actions.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata