Back to skill

Security audit

Automatically logs into email accounts (Gmail, Outlook, QQ Mail, etc.) and generates daily email summaries. Use when the user wants to get a summary of their emails, check important messages, or create daily email digests.

Security checks across malware telemetry and agentic risk

Overview

This skill has a legitimate email-summary purpose, but it needs Review because it gives automation broad access to logged-in mailboxes and encourages storage, scheduling, and optional AI processing of sensitive email data.

Install only if you are comfortable letting browser automation access your logged-in email. Prefer a separate browser profile or limited mailbox, do not type real passwords into command examples, avoid screenshots and saved logs unless necessary, and do not enable scheduled runs or AI extraction unless you intentionally accept recurring access and possible third-party processing of email-derived data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
The skill instructs use of an external AI extraction feature via an environment-stored API key even though the declared tool scope does not make that data flow explicit. This can cause mailbox content to be sent to a third-party service without clear consent or manifest-level disclosure, creating privacy and compliance risk.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation wording is broad enough to trigger on ordinary requests about email help, which could route a user into an automation flow that opens logged-in mailboxes and processes sensitive content. Overbroad matching is dangerous here because the skill handles highly private data and browser sessions.

Missing User Warnings

High
Confidence
95% confidence
Finding
The skill explicitly tells the operator to input an email password into an automation tool without a strong warning against credential capture, reuse, or logging. In a browser automation context, this materially raises the risk of credential exposure, account compromise, and unsafe handling of secrets.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill’s purpose is to extract and summarize mailbox contents, including potentially sensitive personal and business communications, but it lacks an upfront privacy warning and consent framing. Users may not realize that subjects, senders, snippets, screenshots, and summaries could expose confidential data during processing or storage.

Ssd 3

High
Confidence
96% confidence
Finding
The skill instructs harvesting private mailbox data from a logged-in session, including sender names, subjects, snippets, screenshots, page HTML, and AI-generated summaries. This is highly sensitive content, and the collection, local storage, and possible third-party processing paths create significant confidentiality and compliance risk if invoked too broadly or without explicit consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal