Himalaya

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward email CLI skill, but it can access and change a configured mailbox, so users should configure credentials carefully and approve sensitive email actions.

Install only if you want an agent to operate your configured email account through Himalaya. Prefer app passwords, OAuth, `pass`, or a system keyring instead of raw passwords in config files, protect the config file permissions, and require explicit approval before sending, forwarding, reply-all, deleting, moving, exporting full messages, or downloading attachments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file includes plaintext password examples in the main minimal setup, which can normalize insecure practice and lead users to store IMAP/SMTP credentials directly in `config.toml`. If that file is read by other local users, backed up insecurely, committed to source control, or exfiltrated by malware, the email account can be fully compromised.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal