Back to skill

Security audit

Himalaya

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Himalaya email CLI guide with real mailbox command examples, so users should review commands carefully before running them.

Install this only if you want help using the Himalaya CLI. Treat suggested commands as operating on your real mailbox: preview targets first, verify recipients before sending or forwarding, and use extra care with folder delete, purge, expunge, export, and attachment download commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is broad enough to activate on generic email-related requests, which can route the agent into using a powerful email-management skill when the user may only want general advice. In the context of a CLI skill that can read, send, delete, purge, and expunge mail, over-activation increases the chance of unintended sensitive actions or disclosure.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Using absolute language like 'ANY task involving' creates an unconstrained trigger scope that encourages the skill to take over a wide range of email tasks. Because this skill includes operational commands over live mailboxes, excessive applicability raises the risk of acting on the wrong user intent and exposing or modifying email data unnecessarily.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation presents destructive folder operations such as delete, purge, and expunge without prominent warnings that they may permanently remove data. In an agent setting, this omission can normalize unsafe execution and lead to irreversible mailbox loss if the commands are suggested or run without clear user confirmation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.