Back to skill

Security audit

remember-emails

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent, but it sends potentially sensitive email-thread summaries to an external persistent memory API without clear consent, minimization, or retention guidance.

Review this before installing if your email threads include customer, legal, financial, personnel, or confidential business information. Use a scoped and revocable API key, avoid sending full thread contents, redact sensitive details where possible, and confirm BlueColumn's retention and deletion controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to send email-thread contents, including names, contract context, promises, and deadlines, to an external Supabase-hosted API without any explicit privacy warning, consent step, or data-minimization guidance. Email threads often contain sensitive business or personal information, so silently transmitting them to a third-party service creates a real confidentiality and compliance risk.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill metadata states that a live BlueColumn API key is required, but provides no warning about secure credential handling or that actions will access an external service. This can lead users or agents to expose production credentials in unsafe contexts or use them without understanding the trust boundary.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.