Anymail Finder

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Anymail Finder integration, but users should treat email lookup and verification as sensitive contact-data processing.

Install this only if you are comfortable using Membrane as the authentication layer for Anymail Finder and installing its CLI globally. Use it only for email data you are authorized to process, prefer the listed Membrane actions, and review any direct proxy request or mutating API method before it runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly supports finding and verifying email addresses, which involves personal/contact data and potentially outreach-sensitive workflows, yet it provides no warning about privacy, consent, lawful basis, or acceptable-use boundaries. In an agentic setting, this can normalize harvesting or validating personal emails without user friction, increasing the risk of privacy abuse, spam enablement, or policy violations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal