Recipe Save Email Attachments

Security checks across malware telemetry and agentic risk

Overview

This is a small, manual recipe for copying selected Gmail attachments to Google Drive, with expected privacy risk but no hidden or automatic behavior.

Install only if you trust the gws tooling and companion Gmail/Drive skills. Before running it, confirm the Google account, keep the Gmail search query narrow, review the attachment source, and upload only to a Drive folder with appropriate sharing permissions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This recipe moves email attachments from Gmail into Google Drive without any safeguards, warnings, or filtering guidance for sensitive content. Even though the steps are straightforward and likely intended for productivity automation, they can cause inadvertent copying of confidential documents, regulated data, or malicious attachments into broader-access storage locations.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal