email 发布

Security checks across malware telemetry and agentic risk

Overview

This is a simple email-drafting helper that generates editable text and does not request access to accounts, files, credentials, or email-sending tools.

Install only if you want a helper for drafting email text. Review the generated draft before sending it yourself, and avoid including secrets or unnecessary personal data in the prompt.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad everyday requests such as '写封邮件' and '生成邮件', which can cause the skill to activate in many normal conversations without clear user intent to invoke this specific skill. This increases the chance of unintended routing, context confusion, or misuse of user-provided content in situations where a more explicit invocation should be required.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal