Back to skill

Security audit

Save To Email

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned email-sending skill, with privacy and confirmation caveats users should understand before use.

Install only if you intend to send email through Resend. Review recipients, subject, and body before sending, avoid secrets or sensitive records unless authorized, and use a dedicated low-privilege Resend API key where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README instructs users to send recipient addresses, subject lines, and HTML content through the external Resend API but does not clearly warn that this data leaves the local environment and is transmitted to a third-party service. In an agent-skill context, this increases the risk of unintentionally exfiltrating sensitive report contents, personal data, or internal information when a user invokes the skill without understanding the privacy boundary.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This skill sends user-provided recipient addresses and message content to the external Resend service, but the description and usage guidance do not clearly warn about that data transfer or require confirmation before sending. That creates a privacy and data-handling risk, especially if users provide sensitive reports, personal data, or internal content without realizing it will leave the local environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.