Back to skill

Security audit

Outlook-email

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Outlook email skill, but it requires high-impact mailbox access while the actual CLI code is not included in the reviewed bundle.

Review the external CLI source before installing or authenticating. Use the narrowest Microsoft Graph permissions available, test with a non-sensitive mailbox first, confirm every recipient and message body before send or reply actions, and remove stored tokens when you no longer need the tool.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation explicitly advertises the ability to send and reply to emails on the user's behalf, but it does not warn that these actions modify external communications and may create irreversible side effects. In an agent or automation context, this omission increases the risk of unintended outbound messages, accidental data disclosure, or unauthorized communication if the skill is invoked without strong user confirmation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.