Back to skill

Security audit

gmail-wiki-ingest

Security checks across malware telemetry and agentic risk

Overview

The skill fits its Gmail-to-wiki purpose, but it should be reviewed because it handles mailbox metadata on a scheduled basis while its own instructions contradict how it accesses the server.

Install only if you are comfortable with a daily skill that reads Gmail thread metadata and can create review decisions for your wiki. Confirm the HiJavis Gmail ingest switch and read-only Gmail grant match your expectations, and ask the publisher to fix the contradictory execution notes before relying on the bundle broadly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill repeatedly instructs the agent to execute `node scripts/gmail-wiki-ingest.js` for fetch/submit, but the Notes section says there is no `scripts/` directory, no Node runtime, and no local token handling. That contradiction undermines operator trust and can cause the agent or runtime to improvise alternate access paths or fail open, which is risky for a mailbox-processing skill handling gateway-authenticated network operations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.