Back to skill

Security audit

recruit-email-monitor

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: monitors configured recruitment mailboxes, records results locally, and sends Feishu notifications, with sensitive-data risks that users should understand before enabling it.

Install only if you are comfortable giving the skill access to the configured mailboxes and allowing recruitment-email metadata, previews, links, and deadlines to be stored locally and sent to Feishu or the configured Agent/LLM workflow. Use app-specific mail authorization codes, verify the Feishu recipient, review the fixed Excel output path, and disable or adjust full-briefing delivery or stale auto-archival if that does not match your privacy or workflow expectations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Lp3

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding
The skill clearly performs network access, shell execution, and file read/write operations, yet it declares no explicit permissions or trust boundaries. This creates a dangerous transparency gap: users may authorize or install the skill without understanding that it can access mailbox contents, write local files, invoke scripts, and send data externally.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The script automatically rewrites the recruitment tracking spreadsheet and marks pending emails older than 30 days as completed. This can silently alter workflow state and hide unresolved recruiting actions, which exceeds a passive monitoring/briefing role and can cause loss of visibility or missed deadlines.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The guide instructs users to configure mailbox authorization codes, automate mailbox scanning, and send notifications through Feishu, but it does not clearly disclose that email subjects, senders, deadlines, or other extracted content may be transmitted to third-party services and stored in logs or spreadsheets. This creates a real privacy and data-handling risk because users may enable processing of sensitive recruiting communications without informed consent or minimization controls.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README describes automated retrieval, agent-based classification, Excel recording, and Feishu reporting of email-derived data, but it does not clearly warn users that potentially sensitive email content may be processed and transmitted to external systems. In this context, recruitment emails can contain personal data, interview details, links, and account identifiers, so the lack of explicit privacy and consent guidance creates a real data-handling risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends email-derived content to an external AI for judgment and to Feishu for notifications, but the description does not prominently warn users that potentially sensitive mailbox content leaves the local environment. Because recruitment emails can contain personal information, interview links, names, and company correspondence, this omission creates a real privacy and data-handling risk.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill automatically modifies user-managed data stores, including updating Excel workbooks, marking emails as processed, and auto-archiving items after 30 days, without a strong upfront warning about these side effects. This can lead to silent integrity issues, accidental record changes, or loss of visibility into pending recruiting tasks if the automation behaves incorrectly.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The job is configured to automatically send Feishu notifications derived from monitored recruitment emails, but the file contains no explicit privacy guardrails, minimization requirements, or user-facing warning about relaying email-derived content to a third-party messaging channel. Because email content can include personal data, interview details, links, and deadlines, automatic outbound delivery increases the risk of unintended disclosure if summaries include sensitive details or the recipient mapping is misconfigured.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The backup daily briefing task explicitly instructs the agent to forward the complete briefing text to Feishu, which can include all collected recruitment-email details verbatim. Without an explicit warning, consent check, or redaction requirement, this creates a clear privacy exposure path for sensitive personal and job-search information.

Ssd 3

Medium
Confidence
97% confidence
Finding
The instruction to '完整转发简报全文内容' directs verbatim transmission of generated briefing content to Feishu, which defeats data minimization and can expose every collected email detail in a single outbound message. In the context of a recruitment-email monitor, that may include personal identifiers, application status, interview schedules, deadlines, and embedded links, making accidental over-disclosure substantially more likely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.