email-template-builder

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only email template skill with purpose-aligned examples, though its sample tracking helper should be reviewed before production use.

Install is reasonable as a code-generation aid. Before using generated email code in production, restrict UTM tracking to approved marketing or safe domains, exclude unsubscribe, password reset, verification, payment, invoice, signed, and one-time links, and review provider credentials and compliance requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The tracking helper rewrites all HTTP(S) links in outgoing email HTML to append UTM parameters automatically, without any filtering, consent guidance, or allowlist. This can unintentionally modify sensitive links such as signed URLs, password reset links, unsubscribe links, or third-party URLs, potentially breaking security-sensitive flows, leaking identifiers into logs/analytics systems, or undermining privacy expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal