outlook-mail-reader

Security checks across malware telemetry and agentic risk

Overview

This skill is openly for reading Outlook mail through a logged-in local Chrome session, but it gives the agent sensitive mailbox and browser-session access without strong per-task consent or scope limits.

Install only if you are comfortable giving the agent access to your active Chrome session and Outlook mailbox. Use it for narrow, explicit mail queries, avoid broad inbox reads, and consider disabling Chrome remote debugging or removing the MCP config when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill is explicitly designed to control a user's local Chrome session and read Outlook mailbox contents, which exposes highly sensitive personal or corporate communications. Because the description and workflow do not require a clear user-facing consent step, mailbox scope limitation, or privacy warning before accessing existing logged-in sessions, the skill can enable unintended disclosure of email content and metadata.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal