Back to skill

Security audit

sendmux-attachments

Security checks across malware telemetry and agentic risk

Overview

This skill coherently documents Sendmux attachment workflows, with a minor key-scope documentation ambiguity users should verify before use.

Before installing, confirm which Sendmux key is valid for mailbox versus sending endpoints, prefer scoped tokens, keep secrets out of chat, and review file paths and email recipients before uploading or sending attachments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill metadata says SENDMUX_API_KEY is the primary API credential and SENDMUX_MBX_KEY is specifically a mailbox key, but several CLI and HTTP examples use SENDMUX_MBX_KEY for Sending API operations as well. That ambiguity can cause agents or users to apply a broader or incorrect credential to the wrong endpoint, increasing the chance of secret misuse, privilege confusion, and accidental exposure or operational mistakes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.