Back to skill

Security audit

Nylas Email, Calendar & Contacts

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a Nylas email, calendar, and contacts integration, including real send and calendar-change capabilities, with no evidence of hidden or malicious behavior.

Before installing, users should understand that connected Nylas accounts may allow the agent to read email, contacts, and calendars and to perform real actions such as sending messages or changing calendar events. Use appropriately scoped Nylas grants and confirm sensitive send, update, or delete requests before running them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes tools that can send emails, create or modify calendar events, and delete calendar data, but the description does not clearly warn users that these are state-changing actions affecting real external accounts. This can lead users to invoke destructive or privacy-sensitive operations without adequate awareness, increasing the risk of unintended outbound messages, calendar changes, or data loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.