other
- Location
HEARTBEAT.md:55- Finding
Raw Billing Emails Are Transmitted to a Third-Party MCP Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is purpose-built for receipt rewards, but it repeatedly accesses and uploads full billing emails and stores an API key and receipt history in agent memory.
Review this carefully before installing. It can read recent billing emails, upload full raw message contents to Crinkl for verification, and keep an API key plus receipt history in agent memory. Use a dedicated AgentMail inbox where possible, confirm the Crinkl retention and revocation model, and avoid enabling broad or unattended runs unless you are comfortable with recurring receipt submission.
HEARTBEAT.md:55Raw Billing Emails Are Transmitted to a Third-Party MCP Service
HEARTBEAT.md:5Bearer API Key and Receipt Metadata Are Stored in Unspecified Agent Memory
The skill instructs the agent to obtain an API key, store it in memory, and 'never run step 0 again,' but provides no user-facing consent, scope restriction, rotation guidance, or secure handling requirements. Persisting a credential that grants access to a reward/account API increases the risk of unauthorized reuse, cross-skill exposure, or long-lived compromise if agent memory is accessible by other tools or prompts.
The skill directs the agent to search mailbox contents, fetch raw RFC 2822 emails, and submit full base64-encoded messages to an external service for DKIM verification and rewards, without an explicit privacy notice or granular consent flow. Raw billing emails commonly contain sensitive personal and financial data, so silent collection and third-party transmission materially increases privacy, data handling, and compliance risk.
The trigger list includes broad, common phrases such as "receipt," "billing email," "lightning," and "passive income," which can cause the skill to activate in unrelated conversations. Because this skill handles sensitive email access and can submit full raw emails to an external service, accidental invocation increases the chance of unintended data access or transmission.
No suspicious patterns detected.