Gmail Send Email

Security checks across malware telemetry and agentic risk

Overview

This skill transparently tells an agent how to send Gmail messages through the gog CLI, with no hidden scripts or persistence, but users should confirm recipients and content before sending.

Install only if you trust the gog CLI and intend the agent to send email from the configured Gmail account. Before each send, verify the recipient list, subject, body, and authorization to share any sensitive information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill enables outbound email transmission directly through a CLI without any embedded warning, consent checkpoint, or guidance about handling sensitive data. In an agent setting, that creates a real risk of unintended exfiltration, spam, or disclosure of confidential content because the skill operationalizes external communication as a single command.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal