Back to skill

Security audit

Outlook Reader

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly aligned with reading Outlook billing emails, but it handles sensitive mail and attachments with too little user control and suggests automatic forwarding to an AI assistant.

Review this skill before installing or using it with real mail. It should only run against mailboxes and folders you intentionally select, should list matches before downloading, should validate sender and attachment type, should sanitize filenames, and should avoid ZIP extraction or automatic forwarding unless you have an explicit, controlled privacy process.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
read_mail.py:85
Finding

Untrusted Attachment Filename Used as a Filesystem Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
read_mail.py:83
Finding

Automatic Download of Untrusted Email Attachments Without Effective Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:214
Finding

Unsafe Extraction of Untrusted ZIP Attachments

Content
View full analysis
Remediation
View remediation

other

Note
Location
SKILL.md:287
Finding

Automatic Forwarding of Sensitive Financial Email to an Unspecified AI Recipient

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description introduces mailbox reading and attachment download functionality without any warning that it may access sensitive personal or financial communications. In this context, the absence of consent, privacy, and data-handling warnings makes misuse or uninformed use more dangerous because users may not realize the sensitivity or breadth of access involved.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The auto-forwarding automation describes sending matched emails to an AI assistant but provides no privacy notice, consent workflow, or warning about external disclosure. Given that the examples involve billing statements, this omission is especially dangerous because it can result in silent transmission of highly sensitive financial data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are broad and overlap with ordinary user requests about reading Outlook mail, statements, or processing attachments, making unintended activation more likely. In the context of a skill that accesses mailbox contents and saves attachments, accidental triggering can cause privacy-impacting actions without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents recursive enumeration of all Outlook folders and accounts, which materially expands access beyond the stated use case of locating specific billing emails and downloading their attachments. This broader mailbox traversal increases the risk of over-collection of sensitive email metadata and content if the skill is triggered unexpectedly or reused in a wider context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Adding ZIP extraction extends the skill from reading email and saving attachments into processing untrusted archive contents on disk. This creates additional risk such as unpacking malicious files, unsafe archive paths, or exposing more sensitive contents than the user intended to retrieve.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automation guidance recommends automatically forwarding matched emails to an AI assistant, which is a clear data exfiltration pathway beyond the stated purpose of local email reading and attachment download. Because matching may include financial statements or other sensitive mail, auto-forwarding can disclose private data to third parties or external systems without meaningful review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring states the script is for reading Outlook mail and downloading attachments, but the CLI description at L136 only says 'Outlook邮件读取' (Outlook mail reading). In practice, the main workflow creates directories and writes attachment files to disk via SaveAsFile, which is a materially different side effect than merely reading mail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code enumerates inbox messages, reads subjects, sender names, received times, and attachment information, which can expose sensitive personal or business data. While the script name and brief docstring imply email reading, there is no explicit disclosure or caution to the user about accessing mailbox data and processing attachment details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically writes email attachments to a local directory without any confirmation, preview, or safety screening beyond a minimal size check. In a mailbox-processing context, this can cause unintended storage of sensitive documents or unsafe files and increases the risk of users later opening malicious attachments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

文档标题及全部说明均默认以中文呈现,并在常见问题中专门要求设置中文编码,但没有说明这是可选语言还是仅适用于特定中文用户场景。若组织要求不得在无用户选择时强制特定语言/locale,这种默认单一语言表述可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language strings such as the module description and CLI help text are presented only in Chinese, which enforces a specific language experience for users. The file does not indicate that the language choice is optional or that the skill is intentionally limited to a Chinese-speaking environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.