Back to skill

Security audit

Aicoo Inbox Monitoring

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-built for Aicoo inbox monitoring, but it can repeatedly read private inbox and network-request data using an API key with broad triggers and limited consent boundaries.

Install only if you intend to let the skill use your Aicoo API key to read inbox, request, and optional network-context data. Use explicit Aicoo-specific commands, avoid broad recurring monitoring unless you want periodic polling, and prefer the least-privileged token Aicoo supports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is broad and includes generic phrases like 'new messages' and 'pending requests' as well as raw endpoint strings, which can cause the skill to activate in ordinary conversation without clear user intent. Because the skill then directs retrieval of inbox and network data, accidental invocation could expose or process privacy-sensitive information the user did not mean to access.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documentation instructs retrieval of conversations, pending requests, and optional network context without an explicit privacy notice, consent check, or data-minimization guidance. In a monitoring skill, this increases the chance of routine collection and summarization of sensitive communications and relationship metadata beyond what the user specifically intended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.