Back to skill

Security audit

imap-idle-sender

Security checks for vulnerabilities and agentic risk

Overview

This email-to-Feishu notifier is coherent in purpose, but it handles sensitive mailbox content and credentials with incomplete disclosure and weak containment.

Review before installing. Use this only for mailboxes where forwarding excerpts to Feishu is acceptable, avoid putting real secrets directly in the script, restrict file permissions on generated logs and notification JSON, and consider disabling body previews or limiting monitored senders/folders.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/imap_idle.py:35
Finding

Credentials Are Configured Directly in Source Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/imap_idle.py:108
Finding

Sensitive Email Content Is Retained in Plaintext with Default File Permissions

Content
View full analysis
- {email_info['subject']}") # 发送到飞书 send_to_feishu(email_info) ``` ### Technical Analysis Up to 100 notification records are stored in plaintext. Each record can contain the sender’s name and address, message subject, dates, UID, and up to 500 characters of body content. The log separately persists sender and subject metadata. The code creates directories and files ...[truncated 1678 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/imap_idle.py:26
Finding

Third-Party Dependency Is Installed Without Version or Integrity Pinning

Content
View full analysis
pip install imap-tools") sys.exit(1) ``` ### Technical Analysis When `imap-tools` is unavailable, the program directs users to run: ```bash pip install imap-tools ``` No reviewed version, package hash, lockfile, or trusted package-index requirement is specified. The exact code installed can therefore change over time and can also depend on the user’s pip index configuration. Python package installation may execute package build logic in applicable packaging workflows. In addition, the installed package is imported directly by this script and consequently executes with the same operating-system privileges as the listener. A compromised upstream release, package index, or dependency in the resolved dependency tree could therefore obtain access to the process environment, local files, and runtime secrets. The package name observed here is not demonstrated to be a typosquat, and the audit found no evidence that its current upstream release is malicious. The issue is the mutable, unverified installation guidance. ### Attack Path 1. The user runs the Skill without `imap-tools` installed. 2. The script instructs the user to execute an unrestricted `pip install imap-tools`. 3. Pip resolves the latest compatible package and transitive dependencies from its configured index. 4. An upstream account, package release, dependency, or configured index has been compromised. 5. Malicious package code runs during an applicable installation/build step or when the Skill imports the installed module. 6. The malicious code inherits the listener process’s access, potentially including access to source-embedded c ...[truncated 680 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/imap_idle.py (reported line 133)May include surrounding context.

python
FEISHU_APP_SECRET = "******"
FEISHU_USER_ID = "******" 
def get_feishu_token() -> Optional[str]:
    """获取飞书 access token"""
    import urllib.request
    try:
        url = "https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents behavior that reads mailbox data, writes notification files to disk, and sends data over the network, but it does not declare any tool scope or permissions. This creates a transparency and containment problem: users and reviewers cannot easily see the skill’s operational boundaries, increasing the chance of overprivileged or unexpected data access during execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that it forwards sender information, subject lines, and a message summary to Feishu and stores notifications locally, but it does not present a clear privacy warning or data-handling notice. Because email metadata and excerpts may contain sensitive personal or business information, users may unknowingly enable external transmission and local persistence of confidential content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists email-derived data locally in both a JSON file and log file, including sender, subject, UID, timestamps, and potentially body excerpts. This expands data exposure beyond the advertised real-time forwarding behavior and creates additional confidentiality and retention risk if the host is shared, compromised, or backups are accessible.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code extracts message body text or HTML-derived text and includes it in downstream processing, ultimately forwarding content excerpts to Feishu and storing them locally. Forwarding message content, even truncated, materially increases the sensitivity of the data handled and may leak secrets, OTPs, personal data, or confidential business information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script sends email details, including body summaries, to a third-party messaging platform without any interactive consent, warning, or in-script disclosure. In the context of an email-listening skill, this is especially sensitive because incoming mail often contains credentials, personal data, financial details, and internal business content; exfiltration to another platform broadens the trust boundary and compliance exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The user-facing instructions and description are entirely in Chinese, and the file does not offer an alternative language or indicate that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module description and user-facing log/error strings are written exclusively in Chinese, with no indication that the skill is region-specific or that another language can be selected. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.