Back to skill

Security audit

Agentlair Email

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only email API skill whose real email-sending and mailbox access are disclosed and purpose-aligned, though users should treat message data and the API key as sensitive.

Install only if you are comfortable with an agent using AgentLair to create email identities and send or read real email. Confirm recipients, subject, body, and mailbox access before use; keep AGENTLAIR_API_KEY private; avoid sensitive or regulated email unless you have verified AgentLair's retention, deletion, and access-control practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Confidence
90% confidence
Finding
The skill claims 'No data stored beyond delivery' while documenting inbox, outbox, and message-read features that necessarily require some message retention. This can mislead users into sending sensitive content under false privacy assumptions, increasing the risk of unintended external disclosure or compliance violations.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation guidance is broad enough that an agent may use this skill for generic email-related requests without confirming user intent, data sensitivity, or whether external transmission is appropriate. In an agent setting, overly broad activation can cause unnecessary sharing of recipient addresses, message bodies, or mailbox contents with a third-party service.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill does not clearly warn that email content, recipient addresses, and mailbox queries are sent to an external service. Without explicit disclosure, users may unknowingly expose sensitive personal, business, or regulated data to a third party, which is a real security and privacy risk in agent workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.