Back to skill

Security audit

Outlook-email

Security checks for vulnerabilities and agentic risk

Overview

The skill describes a useful Outlook email CLI, but the reviewed package does not include the actual program users are told to run with email credentials and mailbox access.

Review before installing. Only use this if you are comfortable granting a locally run, externally cloned CLI access to your Outlook mailbox and send/reply authority. Prefer a release that includes the full audited executable, pins the source revision and dependencies, documents exact Graph scopes, and explains token storage and revocation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
README.md:16
Finding

Execution of an Unpinned Executable Retrieved from a Mutable Remote Repository

Content
View full analysis

Vulnerability Details

File Location: README.md:16-21, README.md:35-45, and SKILL.md:92-95
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Medium

Vulnerable Code Snippet

README.md:16-21 instructs users to retrieve the implementation from a mutable remote repository:

bash
git clone https://github.com/abhiramee08b021/outlook-cli.git
cd outlook-cli

README.md:35-45 subsequently instructs users to execute that remotely retrieved implementation and provide sensitive credentials:

bash
./outlook configure
# Enter your Client ID and Client Secret when prompted
bash
./outlook auth

SKILL.md:92-95 claims that an executable exists even though it is absent from the audited artifact:

markdown
## Files

- `SKILL.md` - This documentation
- `outlook` - Main CLI script
- `README.md` - Full documentation

Technical Analysis

The audited artifact contains only README.md and SKILL.md; the documented outlook executable is not included. Users are instead directed to clone the current state of an external Git repository and execute its contents without pinning a commit, validating a checksum, or verifying a cryptographic signature.

Because the retrieved revision can change after this skill has been reviewed, the effective executable payload is outside the audit boundary. The external program is also expected to receive an Azure application client secret and OAuth authorization granting access to Outlook mailbox functions. The documentation's assertions regarding restrictive token permissions and transmission only to Microsoft cannot be verified without the missing implementation.

This does not establish that the referenced repository is currently malicious. It establishes an unsafe remote retrieval and execution workflow in which the reviewed documentation does not fix or authenticate the code that users will run.

Attack Pa

...[truncated 1437 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the complete outlook implementation in the audited skill artifact so its credential, token, network, and command-handling behavior can be reviewed.
  2. If external distribution is necessary, reference a specific audited commit or immutable signed release rather than the mutable default branch.
  3. Publish SHA-256 checksums and cryptographic release signatures, and require users or an installer to verify them before execution.
  4. Document the exact Microsoft Graph scopes requested and apply least privilege, separating read and send permissions where practical.
  5. For a native command-line client, prefer OAuth authorization-code flow with PKCE and avoid requiring a reusable client secret where the Microsoft identity platform supports that design.
  6. Document token storage, revocation, expiration, and incident-response procedures.
  7. Add automated release provenance, dependency scanning, and reproducible-build controls to reduce supply-chain risk.

T08 · Insecure Dependencies

Note
Location
README.md:10
Finding

Unpinned and Integrity-Unverified Python Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:10-12
Vulnerability Type: Insecure dependency management
Risk Level: Low

Vulnerable Code Snippet

markdown
### Prerequisites

- Python 3.7+
- `requests` library (`pip install requests`)

Technical Analysis

The installation instructions use an unconstrained pip install requests command. No audited version, lock file, package hash, index restriction, or isolated environment is specified. As a result, the installed dependency can vary over time and cannot be reliably correlated with the version reviewed or tested by the project.

Version pinning alone does not prevent package-index compromise, but pinning combined with hash verification provides stronger integrity and reproducibility. This concern is particularly relevant because the intended application handles Azure credentials, OAuth tokens, and private email data.

The artifact does not demonstrate that the legitimate requests package is malicious. The issue is the absence of dependency version and integrity controls.

Attack Path

  1. A user follows the documented prerequisite command.
  2. pip resolves a package version from its configured package index without a project-supplied version or hash constraint.
  3. A compromised package release, compromised package index, maliciously configured index, or incompatible future release is selected.
  4. Malicious dependency code executes during installation or when imported by the email client.
  5. The dependency accesses process data, local configuration, credentials, OAuth tokens, or email information handled by the application.

Impact Assessment

A malicious dependency executing in the client process would generally inherit the operating-system privileges of the user running the CLI. It could access files available to that user, including the documented configuration directory at ~/.config/outlook-cli/, and could potentially read c ...[truncated 372 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define dependencies in a version-controlled requirements or lock file using an audited, compatible version range.
  2. Generate and require cryptographic hashes, for example through a hash-locked requirements file and pip install --require-hashes.
  3. Explicitly use the official Python Package Index or an authenticated, controlled internal mirror rather than relying on unspecified local index configuration.
  4. Install the application and its dependencies in an isolated virtual environment.
  5. Add automated dependency vulnerability and update monitoring.
  6. Test dependency updates before changing the lock file, and review transitive dependency changes where applicable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
- `SKILL.md` - This documentation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation advertises sending and replying to emails through Microsoft Graph API but does not clearly warn that recipients, subject lines, message bodies, and related metadata will be transmitted to Microsoft services. This can lead users to unintentionally expose sensitive communications or personal data, especially in agent-driven workflows where users may assume actions are local unless explicitly disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.