Email check and vaildation

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward email-validation helper that sends the email address to apipick using a required API key.

Install only if you are comfortable sending the email addresses you check to apipick. Use APIPICK_API_KEY as an environment variable rather than pasting long-lived keys into chat, and avoid checking sensitive or bulk personal email lists without authorization and a review of apipick's privacy and retention terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README encourages users to submit email addresses to a third-party API but does not clearly disclose the privacy and data-sharing implications. Email addresses are often personal data, and sending them to an external service without an explicit warning can lead to unintended exposure, compliance issues, or misuse of sensitive user/customer information.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends user-provided email addresses to a third-party service, but the description and usage guidance do not clearly disclose that data transfer or its privacy implications. Email addresses are personal data in many contexts, so users may unknowingly share sensitive contact information with an external provider, creating privacy, compliance, and trust risks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal