Back to skill

Security audit

Email Helper

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal email-writing skill with somewhat broad activation wording, not evidence of hidden or unsafe behavior.

Before installing, understand that ordinary requests to write or reply to emails may activate this skill. Use it only where you are comfortable having the agent process email text, and prefer explicit activation wording if your environment supports it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example invocations are very broad, everyday phrases such as asking to write a leave email or thank-you email. In assistant ecosystems that route by natural-language matching, generic triggers can cause the skill to activate unintentionally during ordinary conversation, leading to unexpected handling of user content or confusion about which capability is in use.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords and scenarios are very broad and overlap with common everyday requests such as writing or replying to emails. In an agent environment, this can cause the skill to activate unexpectedly for many unrelated user prompts, increasing the chance of inappropriate file access or unintended workflow execution under the declared file read/write permission.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.