Inbox Monitoring

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Pulse inbox-monitoring helper that reads inbox and network-request data with an API key, so it is sensitive but purpose-aligned.

Install only if you want an agent to read Pulse inbox, pending request, and optional network-context data. Use the narrowest view and limit that meet your need, avoid logging full message contents, confirm before running broad or recurring checks, protect PULSE_API_KEY, and review any external cron script before scheduling it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This skill accesses privacy-sensitive inbox, network request, and relationship context data using an API key, but it does not instruct the agent to obtain user confirmation, minimize scope, or warn that personal communications and network metadata will be retrieved. In an automation or broad-trigger setting, this can lead to silent overcollection of sensitive data and unintended exposure in summaries, logs, or downstream actions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal