Back to skill

Security audit

alimail

Security checks across malware telemetry and agentic risk

Overview

This skill does the advertised AliMail employee-directory lookup and shows no hidden install, persistence, destructive action, or unrelated data transfer.

Install only in workspaces authorized to query internal AliMail employee-directory data. Use scoped AliMail OAuth credentials, restrict the skill to users with a legitimate business need, and prefer explicit lookup prompts or confirmation before searching names mentioned in conversation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The instruction that the AI should automatically recognize and search for names mentioned by users is overly broad and can trigger on ordinary conversation without clear user intent to perform a directory lookup. In this context, that can cause unintended disclosure of internal employee email addresses, employee numbers, and department-linked identity information.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill presents directory lookup as a convenience feature but does not clearly warn that it retrieves potentially sensitive internal employee directory data, including email and employee identifiers. Because the data concerns internal staff records, insufficient disclosure increases the chance of casual or uninformed use that violates privacy expectations or internal access policies.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill sends user-provided employee name queries to a remote AliMail directory API, which exposes potentially sensitive internal employee lookup activity and personal data to an external service. In this context the skill’s stated purpose is exactly enterprise employee lookup, so the behavior is intentional, but it still creates a privacy/security risk if users are not clearly informed and if access controls are weak.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.