Back to skill

Security audit

Agnic Agent Email

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed email-management skill for Agnic agents, with sensitive email access that fits its purpose but should be used carefully.

Install only if you want an agent-managed Agnic email address. Treat inbox contents, recipients, subjects, bodies, and AGNIC_TOKEN as sensitive; review the exact recipient, subject, and body before any send or reply command, and make sure you trust the Agnic npm package before running `npx agnic@latest`.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This skill handles sending and receiving email through an external service, but it does not clearly warn users that message contents, recipients, and inbox data may be transmitted to and stored by a third-party platform. In a privacy-sensitive context like email, missing disclosure can cause users to expose confidential or regulated information without informed consent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.