Back to skill

Security audit

Manage your tuta.com account

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Tuta email client, but it handles email credentials and decrypted mailbox keys in a risky, under-scoped way that users should review before installing.

Install only if you are comfortable giving the skill access to your Tuta mailbox and sending authority. Use a dedicated low-risk account where possible, avoid storing the account password in plaintext config, avoid passing passwords on the command line, place any session file in a private user directory instead of /tmp, delete session files when done, and prefer a pinned virtual environment over the documented system-level pip install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tuta_client.py:264
Finding

Decrypted cryptographic keys and access token stored in a predictable temporary file

Content
View full analysis
dict: return { "access_token": self.access_token, "user_id": self.user_id, "mail_address": self.mail_address, "passphrase_key": base64.b64encode(self.passphrase_key).decode() if self.passphrase_key else None, "user_group_key": base64.b64encode(self.user_group_key).decode() if self.user_group_key else None, "mail_group_key": base64.b64encode(self.mail_group_key).decode() if self.mail_group_key else None, "mail_group_id": self.mail_group_id, "created_at": datetime.utcnow().isoformat(), } def load_session(self, session_file: str): """Restore session from a JSON file.""" with open(session_file) as f: data = json.load(f) self.access_token = data["access_token"] self.user_id = data["user_id"] self.mail_address = data.get("mail_address") self.passphrase_key = base64.b64decode(data["passphrase_key"]) if data.get("passphrase_key") else None self.user_group_key = base64.b64decode(data["user_group_key"]) if data.get("user_group_key") else None self.mail_group_key = base64.b64decode(data["mail_group_key"]) if data.get("mail_group_key") else None self.mail_group_id = data.get("mail_group_id") self.session.headers["accessToken"] = self.access_token def save_session(self, session_file: str): os.makedirs(os.path.dirname(session_file) or ".", exist_ok=True) with open(session_file, "w") as f: json.dump(self._session_dict(), f, indent=2) os.chmod(session_file, 0o600) ``` The documented and command-line default is the predictable path `/tmp/tuta_session.json`: ```python p_login.add_argument("--session-file", default="/tmp/tuta_session.json") p_inbox.add_argument("--session-file", default="/tm ...[truncated 3114 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tuta_client.py:533
Finding

Tuta account password exposed through command-line arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned dependencies installed into the managed system Python environment

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description uses very broad trigger phrases such as 'email', 'mail', and 'read email', which can cause the skill to auto-activate in many unrelated contexts. Because this skill can access stored credentials, read inbox contents, and send messages, overbroad invocation materially raises the risk of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to store a Tuta password in configuration and to write a reusable session file containing an access token and decrypted keys, but it does not warn about the sensitivity of those materials or safe storage practices. In the context of an email skill, this can expose full mailbox access and decrypted message capability if the config or session file is read by other processes or users.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The skill explicitly saves a session file that contains an access token and decrypted keys to /tmp, a commonly shared and lower-trust location. That creates a direct credential-access path: any local process or user able to read the file may gain mailbox access and potentially decrypt protected email content.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

--session-file /tmp/tuta_session.json

text

Saves session (access token + decrypted keys) to the session file. Reuse until it expires.

### List Inbox

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill performs shell execution, network access, and file writes, but the manifest does not declare any tool scope or permissions boundaries. That increases the chance of overbroad execution in an agent environment and makes it harder to enforce least privilege for a skill that handles credentials, sessions, and email content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The client persists a reusable access token plus decrypted passphrase, user group, and mail group keys to a JSON session file. Anyone who can read that file can impersonate the user and decrypt mailbox content, which is especially dangerous in an encrypted-email client because these secrets defeat the protection boundary of end-to-end encryption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Session persistence silently writes access tokens and decrypted cryptographic material to disk, with no user-facing consent or warning. In multi-user systems, backups, logs, temp-file scraping, or endpoint compromise, this creates a durable secret-exposure path that enables account access and message decryption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Accepting the account password via a command-line argument exposes it to process listings, shell history, job-control logs, and telemetry on many systems. This can leak primary credentials to other local users or monitoring tools, enabling full mailbox compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The send request hard-codes "language": "en", imposing a specific locale in outgoing behavior without any user opt-in or configuration path. This matches the policy-violation category for forcing a language or locale choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.