CtrlK
BlogDocsLog inGet started
Tessl Logo

enrich-knowledge-graph

Enrich people in a knowledge graph or wiki with contact and social media information — LinkedIn, email, phone, Twitter/X — using premium enrichment APIs via the agentcash CLI. Use this skill when the user wants to enrich contacts, find someone's LinkedIn or email, fill in missing contact info for people in their wiki or knowledge base, or says 'enrich', 'find contact info', 'look up LinkedIn', 'fill in missing info', or anything about augmenting people/contact pages with external data.

73

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security
Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

The skill fetches enrichment data via external APIs (Minerva, PDL) based on person names and emails from the user's local knowledge graph/wiki.

Report incorrect finding
Low

W012: Unverifiable external dependency detected (runtime URL that controls agent).

What this means

The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.

Why it was flagged

The skill instructs the agent to execute operational API calls via `agentcash fetch` using external URLs (`stableenrich.dev`), which act as runtime dependencies for data enrichment behavior; since `stableenrich.dev` is an unknown/third-party domain without strong first-party enterprise provenance, it presents an unverifiable runtime external dependency classified as high risk.

Repository
Merit-Systems/agentcash-skills
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.