Back to skill

Security audit

Email Usage

Security checks for vulnerabilities and agentic risk

Overview

This email skill mostly does what it says, but it also creates mail accounts via Docker and handles passwords and authentication in ways that need review before installation.

Install only in a controlled mail-admin environment. Treat it as an email administration skill, not just a send/read helper: it needs mailbox passwords, can read inbox metadata, can send mail, and can create persistent accounts through Docker. Prefer revising it to prompt securely for passwords, fail closed on SMTP authentication errors, separate account creation into an admin-only workflow, and correct the metadata before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/send_email.py:16
Finding

SMTP Authentication Failure Silently Downgrades to Unauthenticated Delivery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/send_email.py:27
Finding

Mailbox Passwords Are Exposed Through Command-Line and Process Arguments

Content
View full analysis
<主题> <正文> <发件邮箱> <密码>") sys.exit(1) to_addr = sys.argv[1] subject = sys.argv[2] body = sys.argv[3] from_addr = sys.argv[4] password = sys.argv[5] username = from_addr send_email(to_addr, subject, body, from_addr, username, password) ``` `scripts/read_email.py`: ```python if __name__ == '__main__': user = sys.argv[1] if len(sys.argv) > 1 else 'xxx@example.com' password = sys.argv[2] if len(sys.argv) > 2 else 'yourpassword' limit = int(sys.argv[3]) if len(sys.argv) > 3 else 5 read_inbox(user, password, limit) ``` `scripts/create_email.py`: ```python def create_email(user: str, password: str): """在 DMS 容器内创建邮箱账号。user 格式: name@domain.com""" result = subprocess.run( ['docker', 'exec', 'mailserver', 'setup', 'email', 'add', user, password], capture_output=True, timeout=30 ) ``` ```python if __name__ == '__main__': if len(sys.argv) < 3: print("用法: python3 create_email.py <邮箱> <密码>") print("示例: python3 create_email.py newuser@axelhu.com securepass") sys.exit(1) user = sys.argv[1] password = sys.argv[2] ok, msg = create_email(user, password) print(msg) sys.exit(0 if ok else 1) ``` The documented invocation pattern in `SKILL.md` similarly instructs users to place passwords directly in command arguments: ```bash python3 skills/email-usage/scripts/send_email.py <收件人> <主题> <正文> <发件邮箱> <密码> ``` ### Technical Analysis All three operations accept passwords as positional command-line arguments. Depending on the ...[truncated 2025 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
_meta.json:7
Finding

Metadata Incorrectly Declares That No Credentials or Docker Dependency Are Required

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The top-level description says the skill is for sending and receiving mail, but the documentation also includes creating new email accounts, which is a more privileged administrative action. Hiding or omitting account-management capability increases the risk of misuse because users may invoke a seemingly routine mail skill without realizing it can provision identities on the mail system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The top-level description says the skill is for sending and receiving mail, but the documentation also includes creating new email accounts, which is a more privileged administrative action. Hiding or omitting account-management capability increases the risk of misuse because users may invoke a seemingly routine mail skill without realizing it can provision identities on the mail system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The top-level description says the skill is for sending and receiving mail, but the documentation also includes creating new email accounts, which is a more privileged administrative action. Hiding or omitting account-management capability increases the risk of misuse because users may invoke a seemingly routine mail skill without realizing it can provision identities on the mail system.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents use of Python scripts for sending, reading, and creating email accounts, which clearly implies shell execution and network access, but the manifest does not declare any tool scope or permissions. This weakens containment and review because operators cannot easily see that the skill can perform external communications and account-management actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest/description frames the skill as mail sending/receiving, but the documentation instructs users to create new email accounts. This is a sensitive identity-management action that changes system state and can be abused for persistence, impersonation, or unauthorized service access if not clearly disclosed and controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example shows a password directly on the command line, which can leak through shell history, process listings, terminal logs, and audit systems. Because this skill deals with mail credentials, exposure could let an attacker send mail as the user, read mailbox contents, or reuse the password elsewhere if it is shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The IMAP example also places plaintext credentials on the command line, creating the same exposure through process arguments, shell history, and logging. In this case the impact includes unauthorized mailbox access and disclosure of potentially sensitive email contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The account-creation instructions describe a sensitive administrative operation without warning about authorization, audit, naming policy, or downstream security consequences. In context, creating mailbox accounts can enable unauthorized identities, persistence, spam abuse, or accidental creation of weakly protected accounts.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/create_email.py (reported line 7)May include surrounding context.

python
def create_email(user: str, password: str):
    """在 DMS 容器内创建邮箱账号。user 格式: name@domain.com"""
    result = subprocess.run(
        ['docker', 'exec', 'mailserver', 'setup', 'email', 'add', user, password],
        capture_output=True, timeout=30
    )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code logs into an IMAP server and reads messages from the inbox, which is a privacy-sensitive operation involving user data. Although the script prints message metadata after retrieval, there is no prior warning, confirmation, or explicit disclosure in the code that it will access mailbox contents when run.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring at L02 states the script can be run directly as-is. However, the argument check at L27 only rejects fewer than 5 argv entries, while the code unconditionally reads sys.argv[5] at L34, which requires 6 argv entries including the program name. Invoking it per the documented usage can therefore raise an IndexError instead of working directly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script connects with plain SMTP and attempts authentication without requiring TLS, so credentials and message contents may be exposed if the connection is not protected. More seriously, if authentication fails it silently falls back to unauthenticated sending, which can cause mail to be transmitted insecurely or through a misconfigured trusted relay without the user's knowledge.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The natural-language instructions are written as a fixed Chinese-only workflow, including support guidance to contact '小爪子', with no indication that another language is supported or that the locale restriction is intentional. This can violate language/locale policy when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring is written only in Chinese and states the script should be executed directly, with no alternative language or opt-in. This can violate language/locale policy when a skill forces a specific language without documented justification or user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring is written in Chinese and instructs direct execution, and the CLI usage/output strings are also Chinese-only. This imposes a specific language on users without opt-in or explanation, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The command-line help and success output are presented only in Chinese, with no mechanism for user language selection. This is a natural-language policy concern because it forces a locale choice rather than offering or documenting it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.