Back to skill

Security audit

Director Email Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent email-agent purpose, but it exposes sensitive inbox data and action-capable email automation without enough access control or safety boundaries.

Review before installing. Use separate setup-time and runtime Resend keys, require authentication on all inbox read and acknowledgement endpoints, make webhook signature verification mandatory, store inbox data outside public paths with retention limits, and require explicit owner approval before the agent replies, opens links, enters verification codes, or performs external actions based on email content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
references/inboundEmail.js:55
Finding

Webhook Signature Verification Fails Open When the Secret Is Missing

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/inboundEmail.js:103
Finding

Inbox Read and Acknowledgment Endpoints Lack Authentication and Authorization

Content
View full analysis
{ try { const limit = parseInt(req.query.limit) || 50; const files = fs.readdirSync(INBOX_DIR) .filter(f => f.endsWith('.json') && !f.includes('.processed') && f !== '.lastcheck') .sort().reverse().slice(0, limit); const emails = files.map(f => { try { return JSON.parse(fs.readFileSync(path.join(INBOX_DIR, f), 'utf8')); } catch { return null; } }).filter(Boolean); res.json({ emails, count: emails.length }); } catch (err) { res.status(500).json({ error: 'Failed to read inbox' }); } }); // GET /:id — Read specific email (marks as read) router.get('/:id', async (req, res) => { try { const filePath = path.join(INBOX_DIR, `${req.params.id}.json`); if (!fs.existsSync(filePath)) return res.status(404).json({ error: 'Email not found' }); const email = JSON.parse(fs.readFileSync(filePath, 'utf8')); email.read = true; fs.writeFileSync(filePath, JSON.stringify(email, null, 2)); res.json(email); } catch (err) { res.status(500).json({ error: 'Failed to read email' }); } }); // POST /:id/ack — Mark email as processed router.post('/:id/ack', async (req, res) => { try { const filePath = path.join(INBOX_DIR, `${req.params.id}.json`); if (!fs.existsSync(filePath)) return res.status(404).json({ error: 'Email not found' }); const email = JSON.parse(fs.readFileSync(filePath, 'utf8')); email.processed = true; fs.writeFileSync(filePath, JSON.stringify(email, null, 2)); // Rename to .processed to hide from listing fs.renameSync(filePath, `${filePath}.processed`); res.json({ ok: true }); } catch (err) { res.status(500).json({ error: 'Failed to a ...[truncated 1837 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/inboundEmail.js:122
Finding

Unvalidated Message Identifier Is Used to Construct Filesystem Paths

Content
View full analysis
{ try { const filePath = path.join(INBOX_DIR, `${req.params.id}.json`); if (!fs.existsSync(filePath)) return res.status(404).json({ error: 'Email not found' }); const email = JSON.parse(fs.readFileSync(filePath, 'utf8')); email.read = true; fs.writeFileSync(filePath, JSON.stringify(email, null, 2)); res.json(email); } catch (err) { res.status(500).json({ error: 'Failed to read email' }); } }); // POST /:id/ack — Mark email as processed router.post('/:id/ack', async (req, res) => { try { const filePath = path.join(INBOX_DIR, `${req.params.id}.json`); if (!fs.existsSync(filePath)) return res.status(404).json({ error: 'Email not found' }); const email = JSON.parse(fs.readFileSync(filePath, 'utf8')); email.processed = true; fs.writeFileSync(filePath, JSON.stringify(email, null, 2)); // Rename to .processed to hide from listing fs.renameSync(filePath, `${filePath}.processed`); res.json({ ok: true }); } catch (err) { res.status(500).json({ error: 'Failed to ack email' }); } }); ``` ### Technical Analysis `req.params.id` is incorporated directly into a filesystem path without validation. The application does not require the value to match the identifier format generated by the webhook handler, and it does not verify that the normalized path remains inside `INBOX_DIR`. `path.join()` normalizes traversal components but does not itself enforce directory containment. Exploitability depends on how Express, the HTTP server, and any reverse proxy decode or reject encoded path separators and traversal sequences. If a crafted route parameter reaches this code with path separators or equ ...[truncated 1332 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:23
Finding

Untrusted Email Content Is Automatically Supplied to an Action-Capable Agent

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:33
Finding

Runtime Email Operations Are Instructed to Use an Overprivileged Resend API Key

Content
View full analysis
'; const body = { from, to: Array.isArray(to) ? to : [to], subject, text }; if (html) body.html = html; const res = await fetch(`${RESEND_API}/emails`, { method: 'POST', headers: { 'Authorization': `Bearer ${apiKey}`, 'Content-Type': 'application/json' }, body: JSON.stringify(body), }); if (!res.ok) throw new Error(`Resend error ${res.status}: ${await res.text()}`); return res.json(); } ``` ### Technical Analysis Full Resend permissions may be needed temporarily to configure domains or webhooks, but routine runtime sending only requires permission to send email. The Skill does not separate administrative setup credentials from runtime credentials and explicitly requires a full-permission key. This exceeds the minimum privileges necessary for normal send operations. If the agent process, environment, logs, or an injected workflow exposes or misuses the key, the attacker obtains every capability granted to the key rather than only email sending. The observed code sends the API key only to the declared HTTPS Resend endpoint; no deliberate credential exfiltration was found. The issue is credential scope and lifecycle, not an undeclared network destination. ### Attack Path 1. A ...[truncated 914 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broader setup capability for an agent email identity on Resend, including sending, receiving, inbox storage, and automated monitoring. The supplied code chunk only covers the receiving/storage portion: an Express router for Resend inbound webhooks plus endpoints to list, read, and acknowledge stored emails. It does not create or configure an email address, does not send email, and does not implement autonomous monitoring logic. While inbox storage and receiving via webhook are accurately represented, the overall description materially overstates the code's primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
Create `routes/inboundEmail.js` in your Express backend (see `references/inboundEmail.js` for full implementation). Key requirements:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill uses environment secrets and performs network operations but does not declare any explicit tool scope or permission boundary. That increases the chance an agent can invoke the skill with broader-than-expected capabilities, making secret access and outbound calls less visible to users and harder to govern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed for autonomous receipt and handling of email, including verification flows, but it lacks a prominent warning about privacy, consent, and sensitive-content handling. Because email often contains passwords, magic links, invoices, and personal data, silent automation materially increases the risk of overcollection or misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
RESEND_KEY="re_xxxxx"

# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/domains \
  -d '{"name": "yourdomain.com", "region": "us-east-1"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/domains \
  -d '{"name": "yourdomain.com", "region": "us-east-1"}'

# Get DNS records to configure

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/domains \
  -d '{"name": "yourdomain.com", "region": "us-east-1"}'

# Get DNS records to configure

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/domains \
  -d '{"name": "yourdomain.com", "region": "us-east-1"}'

# Get DNS records to configure

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/domains \
  -d '{"name": "yourdomain.com", "region": "us-east-1"}'

# Get DNS records to configure

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/domains \
  -d '{"name": "yourdomain.com", "region": "us-east-1"}'

# Get DNS records to configure

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/domains \
  -d '{"name": "yourdomain.com", "region": "us-east-1"}'

# Get DNS records to configure

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions direct operators to persist inbound emails as JSON on disk without defining retention limits, encryption, access controls, or data-minimization practices. Stored inbox contents can include tokens, personal information, and attachments, so long-lived filesystem storage meaningfully increases exposure after host compromise or accidental publication.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

Step 3: Register Webhook on Resend

bash
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/webhooks \
  -d '{

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The cron-based polling and processed-state workflow creates persistent autonomous monitoring of email over time. That persistence expands the blast radius of prompt-injection-by-email, accidental sensitive-data retention, and unattended actions triggered from untrusted inbound content.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

Step 6: Set Up Inbox Monitoring Cron

Create a cron job that checks for new emails every 5 minutes and notifies the agent:

text
Every 5 min → Check mail/inbox/ for new .json files

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

Send a test email:

bash
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
  -H "Content-Type: application/json" \
  https://api.resend.com/emails \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

js
async function sendEmail(to, subject, text, html) {
  const res = await fetch('https://api.resend.com/emails', {
    method: 'POST',
    headers: {
      'Authorization': `Bearer ${RESEND_API_KEY}`,

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

js
async function getInbox() {
  const res = await fetch('http://localhost:PORT/api/inbound-email');
  const data = await res.json();
  return data.emails;
}

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
references/directorMail.js:20