T09 · Insecure Skill Coding Practices
- Location
scripts/router.js:283- Finding
Shell Command Injection Through Untrusted Email and Configuration Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent support-email router, but it gives a scheduled mailbox workflow unsafe command execution, dynamic package execution, and AI-forwarding authority that users should review carefully.
Install only after fixing or accepting the risks: remove the npx fallback, replace shell-string execSync calls with argument-array execution, validate email addresses/message IDs/config values, restrict csbot to a single approved reporting action and recipient, and validate any generated channel install command before running it. Use a least-privileged mailbox/account because the router is scheduled and processes public inbound email.
scripts/router.js:283Shell Command Injection Through Untrusted Email and Configuration Values
scripts/router.js:316Prompt Injection Through Customer Email Forwarded to a Tool-Enabled AI Agent
scripts/router.js:120Dependency Confusion Risk From Dynamic Execution of an Unscoped npm Package
SKILL.md:166Execution of an Unvalidated Installation Command Obtained From an External Service
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Referenced artifact was not completely inspected
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
const combined = `${subject} ${body}`.toLowerCase();
for (const rule of RULES) {
if (rule.pattern.test(combined)) {
return rule;
}
}
return { name: "unknown", action: "forward_csbot", tag: "[待分类]" };
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest description and top-level documentation present the skill in Chinese only, with no statement that the user may choose their preferred language. This creates a locale/language policy concern because the skill appears to assume Chinese as the operating language rather than offering an explicit opt-in or choice.
The script builds shell command strings and executes them with execSync for search, read, send, and mark operations, using values derived from config files and email metadata. Because these values are interpolated into shell commands, this expands the attack surface from email routing into shell execution, making command injection or unintended command execution possible if quoting assumptions break or a field contains unexpected shell metacharacters.
When mail-cli is not installed, the script falls back to npx mail-cli, which fetches and executes a package at runtime without a pinned version or integrity control. That creates a supply-chain execution risk: a compromised or typosquatted package, or an unexpected latest release, would run with the same privileges as the router and gain access to mailbox contents and local config.
The router forwards full customer email content, sender address, and subject to another mailbox/AI-processing mailbox without any evidence in this file of consent, minimization, or disclosure. In a support context, these emails can contain personal data, account issues, billing details, or incident information, so undisclosed onward transfer materially increases privacy, compliance, and data-handling risk.
The script instructs the AI mailbox to process customer emails and then send a report containing sender details and a summary to another mailbox. This creates an intentional multi-hop disclosure of customer data and increases exposure, especially if the AI mailbox or destination mailbox has different access controls, retention, or audit characteristics than the original support inbox.
The manifest describes support email triage using mail-cli, but this code additionally inspects local configuration files under XDG/APPDATA and environment variables to discover profile information. That local config harvesting is not clearly justified by the stated purpose of routing messages, especially since it reaches outside the immediate inbox-processing flow.
The function accesses local mail-cli configuration files under user config directories to resolve mailbox profile information. This is credential-adjacent/sensitive configuration access, but the file provides no explicit warning or user disclosure beyond implementation comments.
Detected: suspicious.dangerous_exec