T09 · Insecure Skill Coding Practices
- Location
references/inboundEmail.js:55- Finding
Webhook Signature Verification Fails Open When the Secret Is Missing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent email-agent purpose, but it exposes sensitive inbox data and action-capable email automation without enough access control or safety boundaries.
Review before installing. Use separate setup-time and runtime Resend keys, require authentication on all inbox read and acknowledgement endpoints, make webhook signature verification mandatory, store inbox data outside public paths with retention limits, and require explicit owner approval before the agent replies, opens links, enters verification codes, or performs external actions based on email content.
references/inboundEmail.js:55Webhook Signature Verification Fails Open When the Secret Is Missing
references/inboundEmail.js:103Inbox Read and Acknowledgment Endpoints Lack Authentication and Authorization
references/inboundEmail.js:122Unvalidated Message Identifier Is Used to Construct Filesystem Paths
SKILL.md:23Untrusted Email Content Is Automatically Supplied to an Action-Capable Agent
SKILL.md:33Runtime Email Operations Are Instructed to Use an Overprivileged Resend API Key
The declared description presents a broader setup capability for an agent email identity on Resend, including sending, receiving, inbox storage, and automated monitoring. The supplied code chunk only covers the receiving/storage portion: an Express router for Resend inbound webhooks plus endpoints to list, read, and acknowledge stored emails. It does not create or configure an email address, does not send email, and does not implement autonomous monitoring logic. While inbox storage and receiving via webhook are accurately represented, the overall description materially overstates the code's primary purpose and capabilities.
Referenced artifact was not completely inspected
Create `routes/inboundEmail.js` in your Express backend (see `references/inboundEmail.js` for full implementation). Key requirements:
The skill uses environment secrets and performs network operations but does not declare any explicit tool scope or permission boundary. That increases the chance an agent can invoke the skill with broader-than-expected capabilities, making secret access and outbound calls less visible to users and harder to govern.
The skill is explicitly designed for autonomous receipt and handling of email, including verification flows, but it lacks a prominent warning about privacy, consent, and sensitive-content handling. Because email often contains passwords, magic links, invoices, and personal data, silent automation materially increases the risk of overcollection or misuse.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
RESEND_KEY="re_xxxxx"
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/domains \
-d '{"name": "yourdomain.com", "region": "us-east-1"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/domains \
-d '{"name": "yourdomain.com", "region": "us-east-1"}'
# Get DNS records to configure
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/domains \
-d '{"name": "yourdomain.com", "region": "us-east-1"}'
# Get DNS records to configure
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/domains \
-d '{"name": "yourdomain.com", "region": "us-east-1"}'
# Get DNS records to configure
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/domains \
-d '{"name": "yourdomain.com", "region": "us-east-1"}'
# Get DNS records to configure
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/domains \
-d '{"name": "yourdomain.com", "region": "us-east-1"}'
# Get DNS records to configure
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Add domain
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/domains \
-d '{"name": "yourdomain.com", "region": "us-east-1"}'
# Get DNS records to configure
The instructions direct operators to persist inbound emails as JSON on disk without defining retention limits, encryption, access controls, or data-minimization practices. Stored inbox contents can include tokens, personal information, and attachments, so long-lived filesystem storage meaningfully increases exposure after host compromise or accidental publication.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/webhooks \
-d '{
The cron-based polling and processed-state workflow creates persistent autonomous monitoring of email over time. That persistence expands the blast radius of prompt-injection-by-email, accidental sensitive-data retention, and unattended actions triggered from untrusted inbound content.
Create a cron job that checks for new emails every 5 minutes and notifies the agent:
Every 5 min → Check mail/inbox/ for new .json files
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Send a test email:
curl -s -X POST -H "Authorization: Bearer $RESEND_KEY" \
-H "Content-Type: application/json" \
https://api.resend.com/emails \
-d '{
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
async function sendEmail(to, subject, text, html) {
const res = await fetch('https://api.resend.com/emails', {
method: 'POST',
headers: {
'Authorization': `Bearer ${RESEND_API_KEY}`,
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
async function getInbox() {
const res = await fetch('http://localhost:PORT/api/inbound-email');
const data = await res.json();
return data.emails;
}
Detected: suspicious.env_credential_access