Back to skill

Security audit

UniOne Email API

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only UniOne email API skill whose sensitive actions are disclosed and aligned with its email-management purpose.

Install this only if you want an agent to operate your UniOne email account. Use a least-privileged API key if available, require manual review before sends, webhook changes, deletions, project changes, or event exports, and treat webhook callbacks, tracking data, event dumps, and download URLs as sensitive recipient activity data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The webhook section instructs users to configure delivery-event webhooks to an arbitrary URL but does not warn that these callbacks may transmit recipient addresses, engagement events, and unsubscribe/spam data to third-party infrastructure. Without explicit privacy and integrity guidance, users may expose sensitive event data or send it to endpoints they do not control securely.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The event-dump workflow enables bulk export of email activity over large time ranges and returns a download URL, but the documentation omits any warning that this can expose large volumes of recipient and engagement data. In practice, this increases the risk of oversharing, improper retention, or unsafe downstream handling of sensitive operational data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.