Back to skill

Security audit

Recipe Forward Labeled Emails

Security checks across malware telemetry and agentic risk

Overview

This recipe openly forwards Gmail messages, but it can send private email contents to a prefilled address without built-in review or confirmation.

Review carefully before installing or running. Replace the recipient address, use a narrowly scoped label, inspect the message list and contents first, and require an explicit confirmation before any email is sent from your Gmail account.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly retrieves Gmail message content and forwards it to a fixed external recipient without any warning, confirmation, or data minimization. This creates a real risk of unintended disclosure of sensitive email contents, especially because labels like "needs-review" may contain internal, personal, or confidential messages and the recipient address is preconfigured in the recipe.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.