T09 · Insecure Skill Coding Practices
- Location
read_mail.py:85- Finding
Untrusted Attachment Filename Used as a Filesystem Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly aligned with reading Outlook billing emails, but it handles sensitive mail and attachments with too little user control and suggests automatic forwarding to an AI assistant.
Review this skill before installing or using it with real mail. It should only run against mailboxes and folders you intentionally select, should list matches before downloading, should validate sender and attachment type, should sanitize filenames, and should avoid ZIP extraction or automatic forwarding unless you have an explicit, controlled privacy process.
read_mail.py:85Untrusted Attachment Filename Used as a Filesystem Path
read_mail.py:83Automatic Download of Untrusted Email Attachments Without Effective Validation
SKILL.md:214Unsafe Extraction of Untrusted ZIP Attachments
SKILL.md:287Automatic Forwarding of Sensitive Financial Email to an Unspecified AI Recipient
The skill description introduces mailbox reading and attachment download functionality without any warning that it may access sensitive personal or financial communications. In this context, the absence of consent, privacy, and data-handling warnings makes misuse or uninformed use more dangerous because users may not realize the sensitivity or breadth of access involved.
The auto-forwarding automation describes sending matched emails to an AI assistant but provides no privacy notice, consent workflow, or warning about external disclosure. Given that the examples involve billing statements, this omission is especially dangerous because it can result in silent transmission of highly sensitive financial data.
The trigger conditions are broad and overlap with ordinary user requests about reading Outlook mail, statements, or processing attachments, making unintended activation more likely. In the context of a skill that accesses mailbox contents and saves attachments, accidental triggering can cause privacy-impacting actions without sufficiently specific user intent.
The skill documents recursive enumeration of all Outlook folders and accounts, which materially expands access beyond the stated use case of locating specific billing emails and downloading their attachments. This broader mailbox traversal increases the risk of over-collection of sensitive email metadata and content if the skill is triggered unexpectedly or reused in a wider context.
Adding ZIP extraction extends the skill from reading email and saving attachments into processing untrusted archive contents on disk. This creates additional risk such as unpacking malicious files, unsafe archive paths, or exposing more sensitive contents than the user intended to retrieve.
The automation guidance recommends automatically forwarding matched emails to an AI assistant, which is a clear data exfiltration pathway beyond the stated purpose of local email reading and attachment download. Because matching may include financial statements or other sensitive mail, auto-forwarding can disclose private data to third parties or external systems without meaningful review.
The module docstring states the script is for reading Outlook mail and downloading attachments, but the CLI description at L136 only says 'Outlook邮件读取' (Outlook mail reading). In practice, the main workflow creates directories and writes attachment files to disk via SaveAsFile, which is a materially different side effect than merely reading mail.
The code enumerates inbox messages, reads subjects, sender names, received times, and attachment information, which can expose sensitive personal or business data. While the script name and brief docstring imply email reading, there is no explicit disclosure or caution to the user about accessing mailbox data and processing attachment details.
The script automatically writes email attachments to a local directory without any confirmation, preview, or safety screening beyond a minimal size check. In a mailbox-processing context, this can cause unintended storage of sensitive documents or unsafe files and increases the risk of users later opening malicious attachments.
文档标题及全部说明均默认以中文呈现,并在常见问题中专门要求设置中文编码,但没有说明这是可选语言还是仅适用于特定中文用户场景。若组织要求不得在无用户选择时强制特定语言/locale,这种默认单一语言表述可能构成自然语言政策问题。
Natural-language strings such as the module description and CLI help text are presented only in Chinese, which enforces a specific language experience for users. The file does not indicate that the language choice is optional or that the skill is intentionally limited to a Chinese-speaking environment.
No suspicious patterns detected.