Gmail Last5

Security checks across malware telemetry and agentic risk

Overview

The skill is narrowly written to show recent Gmail inbox metadata, but it hard-codes a specific Gmail account and lacks a clear user confirmation step before reading sensitive email data.

Install only if you intend this skill to query Gmail through gog. Before use, remove or replace the hard-coded Gmail address and confirm which account gog is authenticated for, because sender, subject, and date fields can reveal sensitive personal or business information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to access and summarize the user's Gmail inbox contents, which are highly sensitive, but it provides no explicit privacy disclosure, consent checkpoint, or warning about exposing personal email metadata. This creates a real privacy risk because sender, subject, and date fields can reveal confidential relationships, business context, and personal information even if message bodies are not fetched.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal