Back to skill

Security audit

Shitty Email

Security checks across malware telemetry and agentic risk

Overview

This skill openly provides disposable email inbox workflows through one external service, with privacy and acceptable-use caveats users should understand.

Use this only for low-risk temporary inboxes, testing, and disposable signups that comply with the target service's rules. Do not use it for password resets, financial or important accounts, regulated data, private correspondence, or anything where a verification link or code would expose meaningful account access. Treat the session token like a temporary password and delete the inbox when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill routes email contents and session tokens to a third-party disposable email provider but does not warn users that sensitive data will leave the local environment and be stored or processed externally. Because tokens grant inbox access and email bodies may contain verification links or one-time codes, omission of this disclosure can lead to unintended exposure of credentials or personal data.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill explicitly promotes using disposable email for signups and verification flows without documenting consent, terms-of-service, or abuse constraints. In context, this can enable account creation patterns that bypass a service's intended identity, persistence, or anti-abuse expectations, increasing the risk of policy violations and misuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.