Back to skill

Security audit

Pitch Follow-Up Tracker

Security checks across malware telemetry and agentic risk

Overview

This skill is useful for pitch follow-ups, but it asks an agent to inspect sensitive Gmail, drafts, full threads, and possibly memory or off-channel context more broadly than users may expect.

Review before installing. Use only with a Gmail account and pitch tracker you are comfortable letting an agent inspect, and explicitly limit the tracker, contacts, date range, Gmail searches, draft access, full-thread reads, and any memory or off-channel context before running it. Review drafts yourself before creation or sending.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to inspect conversation history, daily memory files, and even context from other channels such as texts, WhatsApp, or calls, which goes beyond the declared data sources of Gmail and the pitch tracker. This creates a scope-expansion/privacy risk because the agent may access unrelated personal or sensitive information to make outreach decisions, violating least-privilege and potentially exposing data not necessary for the task.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README describes broad capabilities and trigger situations such as checking follow-ups, finding who has not replied, and managing outreach status without clearly constraining when Gmail, web search, or local/Sheet data will be accessed. In an agent environment, vague invocation scope can cause the skill to activate in more contexts than users expect, leading to unintended access to email and outreach records.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The description states that the skill checks Gmail for replies and searches for recent brand news, but it does not prominently warn users that it will access external data sources containing potentially sensitive communications and contact information. This creates a transparency and consent risk because users may invoke the skill without realizing it will read inbox content and send data-derived prompts to external search workflows.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger language is broad enough to activate on generic requests like 'outreach status' or 'check follow-ups,' which can cause the skill to run in contexts broader than a narrowly scoped pitch-follow-up workflow. Over-broad activation increases the chance of unintended access to Gmail or tracker data when the user may have meant a different task, leading to accidental data exposure or inappropriate automation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.