T09 · Insecure Skill Coding Practices
- Location
SKILL.md:56- Finding
Unsafe Construction of Shell Commands with User-Supplied Email or Domain Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a legitimate BounceBan email-verification skill, but it can send large contact lists and webhook/export results to external locations without enough built-in privacy safeguards.
Install only if you are comfortable sharing the submitted emails or CSV list data with BounceBan. Get authorization before processing third-party contact lists, avoid uploading extra CSV columns, treat export URLs as secrets, use webhooks only to trusted HTTPS endpoints, and confirm bulk uploads or exports before running them.
SKILL.md:56Unsafe Construction of Shell Commands with User-Supplied Email or Domain Values
webhooks.md:3Webhook Guidance Omits Callback Authentication and Privacy Controls
bulk-verification.md:241Bulk CSV Export Can Expose Unnecessary Source Data Through Bearer Download Links
The README describes verification features and account management but does not prominently warn that submitted email addresses, bulk lists, and account metadata are sent to an external third-party service. This creates a privacy and data-handling risk because users or upstream agents may process personal data without informed consent, especially for bulk email lists that may contain sensitive business or personal contact information.
The trigger examples are broad natural-language phrases such as 'clean this email list' and 'is this a disposable address?', which can match common user requests without clearly signaling that a third-party API call will occur. In an agent environment, ambiguous activation increases the chance of unintended skill invocation and transmission of email addresses or related data to BounceBan without sufficiently explicit user intent.
The skill is explicitly designed to send user-supplied email addresses to BounceBan, a third-party service, but it does not warn the user that their data will leave the local environment or explain retention/privacy implications. Because email addresses are personal data in many contexts, silent transmission can create privacy, compliance, and consent issues even if the API usage is otherwise legitimate.
This example performs an actual external request that includes a user email address in a query parameter sent to BounceBan. In context, the transmission is the core function of the skill, but it still represents a real data exfiltration path to a third party and is risky without explicit user awareness and consent.
Verify one email and wait (recommended default; holds connection up to 80 s):
curl -s "https://api-waterfall.bounceban.com/v1/verify/single?email=someone@example.com" \
-H "Authorization: $BOUNCEBAN_API_KEY"
This bulk verification request sends a list of email addresses to BounceBan, which is a direct third-party transmission of potentially sensitive personal or business contact data. The behavior is functionally intended, but the lack of an explicit privacy/data-sharing warning makes the risk real, especially for large uploaded lists that may contain third-party data.
# 1. Create task -> returns {"id": ...}
curl -s -X POST "https://api.bounceban.com/v1/verify/bulk" \
-H "Authorization: $BOUNCEBAN_API_KEY" -H "Content-Type: application/json" \
-d '{"emails": ["a@example.com", "b@example.com"]}'
# 2. Poll until status=finished
Fetching bulk dump results is an external transmission to the third-party service and may retrieve a dataset derived from user-submitted email addresses. While this call is part of normal operation, it extends the exposure surface of sensitive verification data and should be treated carefully in environments where data-sharing needs explicit disclosure.
curl -s "https://api.bounceban.com/v1/verify/bulk/status?id=TASK_ID"
-H "Authorization: $BOUNCEBAN_API_KEY"
curl -s "https://api.bounceban.com/v1/verify/bulk/dump?id=TASK_ID&page_size=1000"
-H "Authorization: $BOUNCEBAN_API_KEY"
The documentation explicitly states that bulk export returns a public download link for CSV results, which may contain large volumes of email addresses and associated verification metadata. Because the link is public and the file remains accessible for up to 4 hours, anyone who obtains the URL through logs, referrers, chat transcripts, browser history, or accidental sharing can access sensitive data without additional authentication.
The documentation instructs users to send email addresses to a third-party API but provides no privacy notice, consent guidance, or warning that personal data is being transmitted off-platform. Because email addresses are personal data in many contexts, this omission can lead to unintended data sharing, compliance issues, and unsafe use by downstream agents or operators.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.bounceban.com/v1/account
No parameters.
No suspicious patterns detected.