Back to skill

Security audit

Email 163 Tool Free

Security checks across malware telemetry and agentic risk

Overview

This 163 email helper is mostly coherent, but it asks agents to use mailbox credentials and run commands that can send, delete, move, and download mail while its trigger scope and safety controls are too broad.

Install only if you intend to let an agent operate your 163 mailbox. Use a client authorization code rather than your login password, restrict config-file permissions, review recipients and message IDs before any send/delete/move action, and download attachments only to a trusted folder because attachments can contain untrusted files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill's capability coverage includes overly broad trigger language like '消息发送、通知推送、邮件短信、通信集成' that extends far beyond the declared 163 email scope. In an agent environment, this can cause the skill to be selected for generic communication tasks and lead to unintended email actions, credential use, or handling of unrelated user requests under an over-permissive scope.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill exposes destructive and data-affecting operations such as deleting mail, moving messages, creating/deleting folders, and downloading attachments to local storage without explicit confirmation, dry-run guidance, or safety warnings. In an agent setting, this increases the risk of irreversible mailbox changes or writing potentially sensitive or malicious files to disk based on ambiguous prompts.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.