contact-hunter-skill

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external MCP tools (HubSpot, Apollo, and Clay) and web search results without explicit sanitization steps. This creates a surface where malicious content in retrieved professional profiles could influence agent behavior. Ingestion points: HubSpot, Apollo, and Clay MCP tool outputs defined in SKILL.md. Boundary markers: None present. Capability inventory: Local file write to hidden directory (~/.claude/skill-analytics/), MCP tool invocation. Sanitization: None present.
  • [DATA_EXPOSURE]: The skill is configured to record session metrics to a persistent JSON file in a hidden directory (~/.claude/skill-analytics/last-outcome-contact-hunter.json). While described as analytics, this creates a persistent record of the agent's activities on the local filesystem.
  • [METADATA_POISONING]: A discrepancy exists between the author name in config.json ('Tim Kipper') and the author context provided in the skill environment ('scientiacapital').
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:56 AM
Security Audit — agent-trust-hub — contact-hunter-skill