Recipe Create Feedback Form

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple, disclosed recipe for creating a Google feedback form and emailing its link, with the main risk being normal Google account side effects if run without review.

Before running it, verify the active Google account, replace or confirm the recipient address, and review the email subject and body because sending the message will transmit the form link outside your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs sending an email via Gmail to an external recipient address without any warning, confirmation step, or guidance about reviewing recipients and message contents. In an agentic context, this can cause unintended external data transmission, especially if the form URL or surrounding context includes sensitive internal information or if the recipient list is wrong.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal