Back to skill

Security audit

Neomutt Commander

Security checks across malware telemetry and agentic risk

Overview

This email skill is mostly coherent, but its setup asks users to store mailbox credentials in a persistent plaintext NeoMutt config without enough safety guidance.

Review before installing. Use an app-specific password where available, but avoid putting mailbox secrets directly in a synced or shared config file; prefer NeoMutt secret retrieval such as `imap_pass_cmd`, an OS keychain, or a password manager. Keep sending disabled unless you explicitly want the agent to send mail.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.