lobsterMail.ai - instant email for your agent

Security checks across malware telemetry and agentic risk

Overview

This skill transparently provides real email inboxes for agents, but it gives broad authority to create inboxes, receive verification emails, sign up for services, send mail, and run recurring maintenance without enough user-control guidance.

Install only if you are comfortable with a third-party LobsterMail service handling real email contents and metadata. Use it for low-sensitivity agent email tasks, and require explicit approval before signups, verification-code handling, outbound email, billing or verification flows, inbox deletion, or recurring heartbeat checks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README promotes creating and using real email inboxes but does not clearly warn users that messages will be transmitted through a third-party service and may contain sensitive personal or account-recovery data. In an agent context, this can lead users to unknowingly route verification emails, credentials, and other sensitive communications through auto-provisioned infrastructure without informed consent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation normalizes automatic signup behavior (e.g., using the inbox to sign up for services) without warning that this may create third-party accounts or trigger actions on external platforms. For an autonomous agent, that omission is risky because users may not realize the skill can cause account creation, accept terms, or initiate external workflows on their behalf.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill's invocation guidance is very broad, effectively encouraging use for nearly any task involving email, including signups and receipt of verification codes. In an agent setting, this can cause over-triggering and lead to unnecessary use of an external mailbox service for ordinary workflows, increasing privacy exposure and the chance that sensitive account-recovery or authentication messages are routed through a third party.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The description promotes a no-setup email capability but does not clearly warn that message metadata and content will be transmitted to and stored by an external service. Users may assume the capability is local or first-party, causing agents to send sensitive personal, business, or authentication-related email content to a third party without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal