T09 · Insecure Skill Coding Practices
- Location
SKILL.md:35- Finding
SMTP credentials and private email content are disclosed to a remote intermediary
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an email-sending integration, but it asks users to send SMTP passwords and email contents through a remote intermediary with incomplete safety disclosure.
Review before installing. Use only a dedicated, least-privilege app password or service SMTP account, verify every recipient and attachment before sending, avoid confidential content unless you trust AgentPMT with it, and avoid following unpinned npx setup commands without reviewing the referenced skills.
SKILL.md:35SMTP credentials and private email content are disclosed to a remote intermediary
SKILL.md:240Unpinned remote skill installation creates a mutable supply-chain execution path
The description includes broad trigger terms such as send, smtp url, and to, which can cause accidental activation in unrelated contexts. Because this skill performs external email transmission and may handle credentials and recipient addresses, mistaken invocation can lead to privacy breaches or unintended outbound messaging.
The skill explains how to send email, attachments, CC/BCC, and credentials, but does not prominently warn about privacy, mistaken-recipient, and external-transmission risks before use. In this context, omission of such warning increases the chance an agent sends sensitive content or recipient lists without adequate user awareness or confirmation.
The activation keyword list is insufficiently scoped and repeats generic terms that are likely to match unrelated tasks. In an email-sending skill, accidental routing is more dangerous than usual because it can trigger outbound communication to third parties or expose message content and metadata.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/smtp-email-delivery-service
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/smtp-email-delivery-service
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
This skill sends email content and embedded SMTP credentials to an external server, yet the description omits an explicit warning that both secrets and message data will leave the platform boundary. In an agent context, that omission can lead users to provide sensitive credentials, recipient data, and attachments without understanding the trust and exfiltration implications, making misuse and accidental data disclosure more likely.
The example invocation uses https://example.com for smtp_url, contradicting the documented requirement for smtp:// or smtps://. This can cause agents or integrators to build malformed requests, misroute credentials, or fall back to unsafe assumptions when handling SMTP authentication material.
The sample shows attachment content and content_type populated with plain English text rather than the documented base64 content and MIME type, and it shows smtp_url as https://example.com instead of an SMTP/SMTPS URL. This is an active contradiction between the file's example usage and its own documented parameter semantics, which could mislead developers about what the skill actually expects.
No suspicious patterns detected.