Back to skill

Security audit

Skulk Email

Security checks for vulnerabilities and agentic risk

Overview

This email skill appears purpose-aligned, but it handles reusable mailbox credentials in ways that create meaningful account-compromise risk.

Install only if you are comfortable giving the agent mailbox read access and outbound sending authority. Prefer a dedicated mailbox or app-specific password, keep the credential file tightly permissioned, avoid shared hosts, and consider hardening the script so secrets are not passed in process arguments and cookie files are created with mktemp.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skulk-email.sh:43
Finding

Mailbox Passwords Exposed Through Process Command-Line Arguments

Content
View full analysis
/cmdline`, process-monitoring utilities, audit systems, or diagnostic tooling. The exact accessibility of another process's argument vector depends on host configuration and user privileges. Nevertheless, command-line arguments are not an appropriate secret-transfer mechanism because they create an additional disclosure surface that is unnecessary for the declared email functionality. Although the subsequent IMAP authentication uses TLS, transport encryption does not mitigate local disclosure before the password reaches the network connection. ### Attack Path 1. A local attacker obtains the ability to inspect processes belonging to the Skill's user, such as through a compromised process running under the same account, permissive `/proc` configuration, debugging privileges, or elevated local access. 2. The victim invokes an IMAP-backed command such as `inbox`, `read`, `search`, or a Gmail command. 3. The script starts Python with the mailbox password embedded in its argument vector. 4. The attacker monitors process creation or reads the relevant process command line before Python exits. 5. The attacker extracts the DreamHost mailbox password or Gmail application password. 6. The recovered credential is used to authenticate independently to the corresponding mailbox. ### Impact Assessment Successful exploitation exposes the credentials of the mailbox involved in the command. Depending on ...[truncated 474 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skulk-email.sh:12
Finding

Credential File Ownership and Permissions Are Not Enforced

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/skulk-email.sh:141
Finding

Predictable Session-Cookie File in Shared Temporary Directory

Content
View full analysis
` or places a symbolic link at that path. 3. The victim invokes the `send` command. 4. `curl` uses the predictable path as its cookie jar while establishing an authenticated Roundcube session. 5. Depending on platform protections and `curl` file-handling behavior, the attacker may cause a denial of service, redirect output to another accessible path, or gain access to authenticated session-cookie material. 6. If session cookies are recovered before expiration or invalidation, the attacker may attempt to reuse the Roundcube session. This attack requires local access and favorable platform conditions; t ...[truncated 589 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill explicitly instructs users to store mailbox credentials locally in a JSON file and is designed to read them for authentication. Any skill with shell access that can read this path gains reusable email credentials, which can enable inbox exfiltration, impersonation, and account compromise if the host or agent environment is not tightly isolated.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: skulk-email
description: |
  Email via DreamHost — read inbox, send email, search messages. Send works from any VPS (including DigitalOcean) by routing through DreamHost's Roundcube webmail over HTTPS, bypassing SMTP port blocks. Optionally read a shared Gmail inbox via IMAP. Use when: sending email, checking inbox, reading messages, or setting up email for an agent. Dependencies: python3, curl, jq (must be installed on the host). Credentials: DreamHost mailbox email+password stored at ~/.config/skulk-email/credentials.json (user must create this file manually before use; see Setup). No third-party services or API keys needed.
---

# Skulk Email

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This section confirms the skill parses a local credential file containing an email address and password. Because the skill also has network capability, exposure of these secrets is more dangerous in context: stolen credentials can immediately be used to read mail and send messages as the user.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
- **curl** — Roundcube webmail sending
- **jq** — credential file parsing
- **DreamHost mailbox** — email address + password
- **Credential file** — stored locally at `~/.config/skulk-email/credentials.json` (never transmitted beyond DreamHost servers)

## Security

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The setup instructions include a concrete JSON structure for storing both DreamHost and optional Gmail credentials, increasing the likelihood that high-value secrets are persisted on disk in a predictable location. Predictable secret paths materially help any other local process, compromised agent, or malicious skill locate and harvest them.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

mkdir -p ~/.config/skulk-email && chmod 700 ~/.config/skulk-email

text

Create `~/.config/skulk-email/credentials.json`:

```json
{

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Although chmod 600 is good hygiene, this line still reflects continued dependence on a plaintext credential file containing reusable passwords. Strong file permissions reduce accidental exposure but do not protect against compromise by the same user context, malicious local code, or an over-privileged agent.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

Gmail fields are optional — leave empty if you don't need shared Gmail access.

bash
chmod 600 ~/.config/skulk-email/credentials.json

3. Test

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skulk-email.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
# skulk-email.sh — Email for Skulk agents
# Read via IMAP, send via DreamHost Roundcube (HTTPS)
# Credentials: ~/.config/skulk-email/credentials.json
set -euo pipefail

CRED_FILE="$HOME/.config/skulk-email/credentials.json"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skulk-email.sh (reported line 7)May include surrounding context.

sh
#!/usr/bin/env bash
# skulk-email.sh — Email for Skulk agents
# Read via IMAP, send via DreamHost Roundcube (HTTPS)
# Credentials: ~/.config/skulk-email/credentials.json
set -euo pipefail

CRED_FILE="$HOME/.config/skulk-email/credentials.json"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises capabilities that clearly require shell and network access, but it does not declare any tool scope or permission boundaries in the skill manifest. That omission increases the chance an agent may invoke it with broader-than-necessary privileges, especially since it handles credentials and remote connectivity.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: skulk-email
description: |
  Email via DreamHost — read inbox, send email, search messages. Send works from any VPS (including DigitalOcean) by routing through DreamHost's Roundcube webmail over HTTPS, bypassing SMTP port blocks. Optionally read a shared Gmail inbox via IMAP. Use when: sending email, checking inbox, reading messages, or setting up email for an agent. Dependencies: python3, curl, jq (must be installed on the host). Credentials: DreamHost mailbox email+password stored at ~/.config/skulk-email/credentials.json (user must create this file manually before use; see Setup). No third-party services or API keys needed.
---

# Skulk Email

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation text is broad and natural-language friendly ('sending email, checking inbox, reading messages, or setting up email for an agent'), which makes accidental or overly frequent activation more likely. Because the skill can access mailbox contents and send messages, loose triggering materially raises the risk of unintended data access or unauthorized outbound communication.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

2. Store credentials

bash
mkdir -p ~/.config/skulk-email && chmod 700 ~/.config/skulk-email

Create ~/.config/skulk-email/credentials.json:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

Gmail fields are optional — leave empty if you don't need shared Gmail access.

bash
chmod 600 ~/.config/skulk-email/credentials.json

3. Test

Static analysis

No suspicious patterns detected.