If this can be exploited via a skill, then it can be exploited via untrusted input inserted into context. Does Cowork help with reading email?