Back to skill

Security audit

Email Quality Auditor

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed email-audit helper that reads relevant campaign evidence and only writes an audit artifact after explicit authorization.

Install only if you are comfortable providing the auditor with the campaign and provider evidence it needs, including consent, suppression, engagement, and outcome records. Review any proposed persistent audit artifact before authorizing the write.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
The display name, summary, and description embed Chinese text as part of the default skill presentation, but the file does not state that the skill is region-specific or that users may choose their preferred language. This creates a natural-language locale policy concern because the skill imposes bilingual/localized output conventions without explicit opt-in or justification.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
## Persistence

Persist only after explicit authorization to `memory/audits/email/YYYY-MM-DD-<topic>.md`. Preserve the scorer's orthogonal `status` and `verdict`; validate the complete v3 draft with `validate-audit-artifact.py` against the intended `--relative-path`, persist only through one full-content Write, and revalidate the target per the auditor runbook. Edit/shell/MCP mutations of the reserved sink are unsupported. Do not autonomously modify consent, claims, provider settings, or hot cache.

## Reference Materials
Confidence
80% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.