Back to skill

Security audit

Zoho Email Integration

Security checks for vulnerabilities and agentic risk

Overview

This Zoho Mail skill mostly does what it claims, but it handles powerful mailbox tokens in ways that need review before installation.

Review this before installing on any account with sensitive mail. Use a dedicated Zoho OAuth client with the minimum needed scopes, do not set ZOHO_API_BASE_URL or mail server overrides to untrusted hosts, keep token files out of shared directories and CI logs, restrict /email bot commands to trusted users, and use dry-run before bulk delete or cleanup actions. Revoke the Zoho connected app if the token file may have been exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/zoho-email.py:153
Finding

OAuth Bearer Token Disclosure Through an Unrestricted API Endpoint Override

Content
View full analysis
`. 6. The attacker's server records the token and uses ...[truncated 554 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/oauth-setup.py:41
Finding

OAuth Authorization Callback Lacks CSRF State Validation

Content
View full analysis
timeout: print("\n✗ Timeout waiting for authorization") sys.exit(1) code = CallbackHandler.authorization_code ``` ### Technical Analysis The authorization request does not contain an unpredictable OAuth `state` parameter. The local callback handler accepts any request containing a `code` query parameter and does not correlate it with the authorization transaction initiated by the setup process. Binding the callback server to `127.0.0.1` appropriately prevents direct remote access to the listener, but it does not replace transaction correlation. A malicious web page opened in the victim's browser may still cause requests to localhost. Without state validation, the application cannot distinguish the expected callback from an injected callback. The flow also does not implement PKCE. Although PKCE does not replace `state`, it would add protection against authorization-code interception and substitution where supported. ### Attack Path 1. The victim starts t ...[truncated 1164 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/oauth-setup.py:149
Finding

OAuth Token Files Are Written Before Restrictive Permissions Are Applied

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
test-app-password.sh:44
Finding

App-Password Test Script Prints a Live Password Prefix

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:4
Finding

Third-Party Dependency Is Not Reproducibly Pinned

Content
View full analysis
=2.31.0 ``` ### Technical Analysis The requirement permits any current or future `requests` release above version 2.31.0. As a result, two installations from the same project revision can execute different third-party code. No malicious package, typosquatted name, or known-vulnerable resolved version was identified in the audit. The risk is the absence of reproducible version and artifact integrity controls: a future compromised, malicious, or incompatible accepted release could be installed without a corresponding repository change or code review. ### Attack Path 1. A future release accepted by `requests>=2.31.0` becomes compromised or otherwise unsafe. 2. A user performs a fresh installation or dependency upgrade. 3. The package resolver selects the unsafe release. 4. Package installation and subsequent imports execute code that was not represented in the audited project revision. This is a supply-chain hardening weakness rather than evidence that the currently named dependency is malicious. ### Impact Assessment A compromised dependency executes with the privileges of the user installing or running the Skill. Because this Skill processes OAuth tokens, app passwords, and email content, malicious dependency code could access those assets. The exact impact depends on the release selected by the package resolver and the privileges of the runtime account. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (146)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 249)May include surrounding context.

md
#### Technical Details
- Endpoint changed from `PUT /accounts/{id}/messages/{id}` to `PUT /accounts/{id}/updatemessage`
- Delete endpoint now uses `DELETE /accounts/{id}/folders/{folderId}/messages/{id}`
- All message IDs converted to integers for API compatibility
- Added folder caching via `list_folders()` for efficient lookups

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 338)May include surrounding context.

md
### Added - OAuth2 Features
- **OAuth2 authorization code flow** - Interactive browser-based login
- **Automatic token refresh** - Access tokens refresh automatically when expired
- **Secure token storage** - Tokens stored in `~/.clawdbot/zoho-mail-tokens.json` with 600 permissions
- **Token management CLI** - Commands to check status, refresh, and revoke tokens
- **IMAP XOAUTH2 support** - OAuth2 authentication for IMAP connections

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 378)May include surrounding context.

md
### Security Improvements
- **No password storage** - OAuth2 eliminates password storage
- **Token-based auth** - Short-lived access tokens (1 hour)
- **Auto-refresh** - Seamless token renewal
- **Revocable access** - Easy to revoke without changing passwords
- **Secure file permissions** - Token files enforced to 600

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The documentation states that the token file contains the client secret, access token, and refresh token, and also notes the file is not encrypted. A stolen refresh token and client secret can allow long-lived unauthorized access to the mailbox, so documenting and normalizing plaintext storage of all secrets in one file increases credential-compromise risk.

Content

Scanner excerpt · OAUTH2_SETUP.md (reported line 208)May include surrounding context.

md
### Security

- **Permissions:** 600 (owner read/write only)
- **Contents:** Client ID, Client Secret, Access Token, Refresh Token
- **Encryption:** Not encrypted (store in secure location)
- **Version control:** Add to `.gitignore`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · OAUTH2_SETUP.md (reported line 265)May include surrounding context.

If refresh fails:

bash
# Delete old tokens and set up again
rm ~/.clawdbot/zoho-mail-tokens.json
python3 scripts/oauth-setup.py

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · OAUTH2_SETUP.md (reported line 318)May include surrounding context.

If refresh fails:

bash
# Delete old tokens and set up again
rm ~/.clawdbot/zoho-mail-tokens.json
python3 scripts/oauth-setup.py

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 61)May include surrounding context.

Attack Vector:

bash
/email search "; rm -rf /; echo "
/email search `whoami`
/email search $(cat /etc/passwd)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SECURITY-AUDIT-SUMMARY.md (reported line 28)May include surrounding context.

Attack Vector:

bash
/email search "; rm -rf /; echo "
/email search `whoami`
/email search $(cat /etc/passwd)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SECURITY.md (reported line 95)May include surrounding context.

Attack Vector:

bash
/email search "; rm -rf /; echo "
/email search `whoami`
/email search $(cat /etc/passwd)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY-AUDIT-SUMMARY.md (reported line 30)May include surrounding context.

bash
/email search "; rm -rf /; echo "
/email search `whoami`
/email search $(cat /etc/passwd)

Fix:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SECURITY.md (reported line 15)May include surrounding context.

Attack Example:

javascript
/email search "; rm -rf ~; echo "

Fix: New email-command-SECURE.js uses spawn() with argument arrays instead of shell interpolation. No shell metacharacters are processed.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · CHANGELOG.md (reported line 61)May include surrounding context.

Attack Example:

javascript
/email search "; rm -rf ~; echo "

Fix: New email-command-SECURE.js uses spawn() with argument arrays instead of shell interpolation. No shell metacharacters are processed.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SECURITY-AUDIT-SUMMARY.md (reported line 28)May include surrounding context.

Attack Example:

javascript
/email search "; rm -rf ~; echo "

Fix: New email-command-SECURE.js uses spawn() with argument arrays instead of shell interpolation. No shell metacharacters are processed.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SECURITY.md (reported line 15)May include surrounding context.

Attack Example:

javascript
/email search "; rm -rf ~; echo "

Fix: New email-command-SECURE.js uses spawn() with argument arrays instead of shell interpolation. No shell metacharacters are processed.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SECURITY.md (reported line 95)May include surrounding context.

Attack Example:

javascript
/email search "; rm -rf ~; echo "

Fix: New email-command-SECURE.js uses spawn() with argument arrays instead of shell interpolation. No shell metacharacters are processed.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 61)May include surrounding context.

md
**Attack Example:**
An attacker could send an email with an attachment named:
- `../../../../etc/cron.d/backdoor` - Write to system cron
- `~/.ssh/authorized_keys` - Add SSH keys for persistence  
- `../../.bashrc` - Execute code on shell login

**Fix:** Implemented `_sanitize_filename()` function that:

YARA rule 'agent_skill_destructive_autonomous_actions': Autonomous destructive filesystem, shell history, or repository actions in AI agent skills [agent_skills]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SECURITY.md (reported line 95)May include surrounding context.

_output_path = safe_filename with open(safe_output_path, 'wb') as f: f.write(payload)

text

#### 6. Command Injection in Test Script (HIGH)

**Issue:** The `test-app-password.sh` script used `eval` to execute test commands with environment variables (`TEST_EMAIL`), allowing command injection if a malicious email address was provided.

**Attack Example:**
```bash
TEST_EMAIL="user@example.com' ; rm -rf / ; echo '" ./test-app-password.sh

Fix:

  1. Replaced eval with bash -c for safer command execution
  2. Added regex validation of TEST_RECIPIENT email format before any command execution
  3. Validation regex: ^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$

Impact: Prevents arbitrary command execution during testing. Script now exits immediately if an invalid email address is detected.


Security Best Practices

1. Credential Management

OAuth2 (Recommended):

bash
# Run interactive setup
python3 scripts/oauth-setup.py

# Verify token file permissions

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This variant includes a meaningful security concern beyond mere mismatch: the skill metadata and instructions normalize local storage of secrets and tokens in predictable paths under the user's home directory. While local token storage is common, documenting it without clear permission scoping, secure file creation practices, or encryption increases credential exposure risk on multi-user or poorly secured systems.

Content

No source excerpt is available for this finding.