Neynar Inbox

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward email API skill; the main risks are trusting the service with email data and confirming before sending or deleting mail.

Install only if you trust Neynar Inbox with the emails and mailbox metadata handled by the skill. Store generated API keys in a secret store, require explicit confirmation before sending or deleting email or mailboxes, and only register webhooks or polling schedules that you intentionally control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The API reference includes destructive DELETE endpoints for mailboxes and emails without prominent warnings or confirmation guidance. In an agent context, this increases the chance of accidental irreversible data loss if the model invokes these endpoints without explicit user consent or safety checks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal