Thrd Skill

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Thrd email-inbox integration with disclosed API-key, network, billing, cache, and polling behavior.

Install this only if you want an agent to operate a dedicated Thrd inbox. Keep THRD_API_KEY in a secret manager, reveal onboarding keys only in a trusted terminal, supervise long-running polling, and require human approval for outbound email and billing checkout flows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill declares only runtime requirements under metadata but does not explicitly disclose the sensitive capabilities it exercises: environment secret access, network access, and local file read/write. That under-specification matters because the skill can read THRD_API_KEY, call remote services, and persist local state such as cached OpenAPI data or cursor files, which expands the trust boundary beyond what a consumer may expect.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding
The description emphasizes inbox provisioning and safe email operations, but the documented behavior also includes billing checkout generation and downloading/caching the remote OpenAPI contract to disk. These extra behaviors are not obviously implied by the headline purpose, so operators may authorize the skill without realizing it can initiate billing-related flows or write fetched remote content locally.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal