Cold Email Outreach System

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's instructions match its stated purpose (finding leads and sending emails) but its metadata omits required credentials and there are practical/privacy risks from automating outbound email that you should understand before installing.

This skill appears to do what it says, but its registry metadata is incomplete: SKILL.md requires SENDCLAW_API_KEY but the skill does not declare it. Before installing, confirm you trust SendClaw and are willing to provide an API key (only provide secrets to trusted skills). Consider: - Add SENDCLAW_API_KEY to the skill metadata or only set the env var when you intentionally use the skill. - Be aware this automates outbound emails — check legal/anti-spam rules (CAN‑SPAM, GDPR) and ensure you have permission to contact targets. - Verify the 'from' address and ownership/permission to send as that identity. - If you don’t want the agent to send emails autonomously on a schedule, disable autonomous invocation or only run the skill manually. - Keep an eye on rate limits (GitHub unauthenticated searches are limited) and SendClaw free-tier restrictions. If you want this skill, request the owner update the registry metadata to declare SENDCLAW_API_KEY (and any other credentials) so the permission model accurately reflects runtime needs.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal