Back to skill

Security audit

himalaya

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent email CLI helper, but users should treat it like any tool that can access, send, and modify email.

Install only if you intend to let Himalaya access your email account. Use a keyring or password manager rather than raw passwords in config, review recipients and attachments before sending, and confirm before deleting, moving, or bulk-changing messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/configuration.md (reported line 50)May include surrounding context.

System keyring (requires keyring feature)

toml
backend.auth.keyring = "imap-example"

Then run himalaya account configure <account> to store the password.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file includes plaintext password configuration examples in the main minimal setup, which can normalize storing mail credentials directly in config.toml. Users may copy the example into real environments, leaving long-lived IMAP/SMTP credentials exposed to local compromise, backups, logs, or accidental disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is described as a mail CLI for IMAP/SMTP operations, but this configuration reference documents use of backend.auth.cmd to execute arbitrary shell commands for password retrieval. Spawning local commands is a broader capability than mail handling itself and is not explicitly reflected in the manifest description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The OAuth2 examples instruct the skill to obtain secrets and tokens by running external commands via *.cmd settings. Executing local commands to fetch sensitive material is a significant capability not justified by the manifest's simple description of email list/read/search/compose/reply/forward/copy/move/delete behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation shows MML attachment and inline-image examples that reference local filesystem paths, but it does not explicitly warn that those paths will be read from disk and included in the outgoing email. In a mail-composition tool, this can lead to accidental exfiltration of sensitive local files if users copy examples or misunderstand what filename=/path/... does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This file explains how to compose and send messages from the CLI, including template send, but does not include a user-facing warning about the privacy impact of transmitting message bodies, headers, and attachments. For markdown files, omissions of warnings about actions affecting user data or privacy are in scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.