Back to skill

Security audit

Automatically logs into email accounts (Gmail, Outlook, QQ Mail, etc.) and generates daily email summaries. Use when the user wants to get a summary of their emails, check important messages, or create daily email digests.

Security checks for vulnerabilities and agentic risk

Overview

The skill’s email-summary purpose is coherent, but it handles private mailbox access in ways that need review before installation.

Install only if you are comfortable granting browser automation access to your logged-in email. Avoid typing real passwords into shell commands, avoid saving inbox screenshots unless needed, store outputs in a private directory, and do not enable cron or launchd scheduling unless you understand how to disable it and protect the script and logs.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:215
Finding

Persistent Daily Execution Through Cron and a macOS LaunchAgent

Content
View full analysis
> /path/to/logs/email_summary.log 2>&1 ``` ```xml Label com.email.dailysummary ProgramArguments /bin/bash /path/to/email_daily_summary.sh StartCalendarInterval Hour 9 Minute 0 StandardOutPath /tmp/email_summary.log StandardErrorPath /tmp/email_summary_error.log ``` ```bash launchctl load ~/Library/LaunchAgents/com.email.dailysummary.plist ``` ### Technical Analysis The Skill instructs users to register a cron entry or load a macOS LaunchAgent that invokes a shell script every day. Both mechanisms survive the original Skill invocation and continue executing until explicitly removed. Scheduled execution is consistent with the optional daily-automation feature, but it is not required for the core function of producing an email summary on demand. It therefore exceeds the minimum privileges and lifecycle needed for the basic task. The documentation does not provide an uninstall procedure, verify the integrity or ownership of the referenced script, enforce restrictive file permissions, or require an explicit security confirmation before enabling persistence. Because the scheduler invokes a mutable filesystem path through `/bin/bash`, any party able to replace or modify that script can convert the legi ...[truncated 1192 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Unpinned Third-Party Browser Automation Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:54
Finding

Email Password Exposed Through a Command-Line Argument

Content
View full analysis
"your-password" ``` ### Technical Analysis The manual login example instructs the user to substitute an email password directly into a shell command. A real password entered this way may be stored in shell history, captured by terminal recording or support tooling, exposed in copied command transcripts, or temporarily visible through process inspection depending on how the CLI handles its arguments. This conflicts with the document's later recommendation not to store passwords in plaintext. Even if the browser automation tool does not persist the password itself, placing the secret in the command line creates exposure outside the tool's control. ### Attack Path 1. The user replaces the placeholder with a real mailbox password. 2. The shell records the command in history, or another local monitoring mechanism captures the command line. 3. A local user, malicious process, backup reader, or support operator obtains the recorded command. 4. The exposed credential is used to authenticate to the mailbox. 5. If multifactor authentication is absent, bypassed, or separately compromised, the attacker obtains mailbox access. ### Impact Assessment Exposure may permit unauthorized access to the user's email account, including reading sensitive messages, resetting passwords for other services, impersonating the user, and accessing attachments or account recovery communications. The exact impact depends on provider controls such as multifactor authentication, login alerts, and session restrictions. The vulnerable example does not itself provide elevated operating-system privileges. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to type their email password directly into a shell command, which can expose credentials through shell history, terminal scrollback, process inspection, logging, or agent transcripts. In the context of email access, compromise of the password can lead to full mailbox takeover and potentially account recovery abuse across other services.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly directs collection and preservation of mailbox contents and screenshots into local files and reports. Because email data commonly contains sensitive personal, business, and security-related information, this creates a meaningful data exposure path even without network exfiltration code.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The AI-summary step instructs extraction of sender, subject, and message summary from live mailbox contents, which exposes private communications to an AI processing workflow and potentially to external services depending on tool configuration. In the context of email, even summarized content can reveal confidential business, financial, or personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends saving screenshots of inbox contents without warning that screenshots may capture sensitive email subjects, senders, previews, or other private information. These files can persist locally, be synced to cloud backups, or be accessed by other users/processes on the system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill recommends scheduled automated execution against personal email accounts, creating recurring access to private mailbox data and likely generating local artifacts such as logs and screenshots. Persistent automation increases the blast radius of session misuse and privacy exposure if the host or stored outputs are compromised.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

bash
# 编辑 crontab
crontab -e

# 添加每日早上 9 点执行的任务
0 9 * * * /path/to/email_daily_summary.sh >> /path/to/logs/email_summary.log 2>&1

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

macOS (launchd)

创建 ~/Library/LaunchAgents/com.email.dailysummary.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

macOS (launchd)

创建 ~/Library/LaunchAgents/com.email.dailysummary.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

macOS (launchd)

创建 ~/Library/LaunchAgents/com.email.dailysummary.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

macOS (launchd)

创建 ~/Library/LaunchAgents/com.email.dailysummary.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The launchd example writes stdout and stderr to /tmp log files, which may capture mailbox metadata, page state, errors, or other sensitive details in a world-accessible or weakly protected temporary location. In the context of email automation, logging to /tmp materially increases the chance of local data exposure.

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

StandardErrorPath /tmp/email_summary_error.log

text

加载任务:

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

加载任务:

bash
launchctl load ~/Library/LaunchAgents/com.email.dailysummary.plist

输出示例

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Most user-facing instructions in the skill are presented in Chinese, which can impose a language requirement on users without opt-in. The policy requires avoiding forced language or locale constraints unless users are given a choice or the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a browser-based email summarization skill, and the documented implementation primarily uses browser-use to reuse logged-in sessions or perform manual login in the browser. Advising use of environment variables for sensitive data introduces a credential-handling capability outside the obvious scope of the stated purpose and beyond what this skill otherwise documents as necessary.

Content

No source excerpt is available for this finding.