Back to skill

Security audit

email-reporter

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says by emailing reports, but its implementation has serious unsafe paths that can expose reports, SMTP credentials, or even allow command execution through the msmtp backend.

Review this skill carefully before installing. Use the SMTP backend only, avoid enabling msmtp until the shell command and temporary-file handling are fixed, do not send unreviewed reports, and avoid storing SMTP credentials in the plaintext config file unless permissions are locked down and the credential is a limited app password.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
send_attachment.py:115
Finding

OS Command Injection Through the msmtp Recipient Argument

Content
View full analysis
/tmp/email-reporter-pwned # ``` 3. `email_reporter.py` forwards the recipient to `send_attachment.py`. 4. `send_via_msmtp()` constructs the following effective shell command: ```sh cat /tmp/email_reporter_msg.eml | msmtp -t victim@example.com; id > /tmp/email-reporter-pwned # ``` 5. The shell executes the injected command with the privileges of the user or agent running the skill. ### Impact Assessment Successful exploitation provides arbitrary command execution under the account running the email reporter. An attacker could read or alter files available to that account, steal environment variables and SMTP credentials, modify reports, invoke network tools, or use the compromised proc ...[truncated 198 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
send_attachment.py:111
Finding

Unsafe Predictable Temporary Email File

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
email_reporter.py:179
Finding

SMTP Credentials Stored in a Plaintext Configuration File Without Enforced Permissions

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
md2pdf.py:48
Finding

Untrusted Markdown Can Trigger Local and Remote Resource Access During PDF Rendering

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation advertises benign report conversion and delivery, but also introduces hidden operational requirements such as SMTP backends and credential-based outbound communication without corresponding permission disclosure. Description-behavior mismatch is dangerous in agent skills because users may authorize local formatting while unintentionally enabling exfiltration of report contents to external email recipients.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation advertises benign report conversion and delivery, but also introduces hidden operational requirements such as SMTP backends and credential-based outbound communication without corresponding permission disclosure. Description-behavior mismatch is dangerous in agent skills because users may authorize local formatting while unintentionally enabling exfiltration of report contents to external email recipients.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · email_reporter.py (reported line 178)May include surrounding context.

python
]
        
        # Pass config via environment
        env = os.environ.copy()
        env["EMAIL_SENDER"] = sender
        env["EMAIL_SMTP_HOST"] = config.get("smtp_host", "smtp.qq.com")
        env["EMAIL_SMTP_PORT"] = str(config.get("smtp_port", 587))

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill's purpose is ordinary email reporting, yet the msmtp backend executes a shell pipeline incorporating recipient input. That unnecessary shell usage expands a simple mail-sending feature into a command-execution surface, making exploitation plausible in any workflow where an agent or user can influence the recipient address.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a classic tool-parameter abuse issue: attacker-controlled data is interpolated into a shell command that invokes a powerful system tool. In an agent skill context, this is more dangerous because recipients may be dynamically derived from external inputs, turning a reporting utility into an RCE primitive.

Content

Scanner excerpt · send_attachment.py (reported line 117)May include surrounding context.

python
f.write(msg.as_bytes())
    
    cmd = f'cat {temp_file} | msmtp -t {to_addr}'
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    
    return result.returncode == 0

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly promotes emailing generated reports and PDF attachments but provides no warning that agent reports may contain sensitive data, secrets, internal findings, or personal information. In an agent tooling context, this omission can lead users to exfiltrate sensitive content to unintended or external recipients through normal use of the skill.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 15)May include surrounding context.

pip install markdown weasyprint

For Ubuntu/Debian - install system dependencies

sudo apt-get install libpango-1.0-0 libpangoft2-1.0-0

text

## Configuration

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

pip install markdown weasyprint

For Ubuntu/Debian - install system dependencies

sudo apt-get install libpango-1.0-0 libpangoft2-1.0-0

text

## Configuration

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents use of environment variables, local config files, subprocess execution, and package/system installation steps, but it declares no permissions or tool scope. In an agent ecosystem, that omission weakens user consent and policy enforcement because the skill can access sensitive configuration and invoke shell-capable workflows without explicit disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to send reports and attachments externally by email, yet the description lacks a clear warning that local report contents may leave the environment. In an agent context, reports often contain analysis results, file excerpts, or secrets, so undisclosed outbound transmission materially increases data leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration examples encourage storing SMTP credentials in environment variables and a plaintext file under the user's home directory without warning about credential sensitivity or file permission hardening. This can lead to accidental credential exposure via shell history, process inspection, backups, or permissive filesystem access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill recommends persisting SMTP credentials in a home-directory config file, creating long-lived sensitive state on disk. Persistent credential storage increases the blast radius of host compromise, account sharing, backups, and accidental disclosure, especially when no file permission requirements or secret-handling guidance are provided.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Option 2: Config File

Create ~/.email_reporter.conf:

json
{

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill reads SMTP credentials from environment variables and a local config file, giving it access to reusable email secrets and outbound messaging capability. In an agent setting, this increases the blast radius of compromise and enables silent exfiltration of sensitive reports through external email channels.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · email_reporter.py (reported line 125)May include surrounding context.

python
# Try shared utils
                md2pdf_script = Path("shared/utils/md2pdf.py")
            
            subprocess.run([
                'python3', str(md2pdf_script),
                str(report_path),
                str(pdf_path)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends report content and attachments to an external recipient without any explicit warning, confirmation, classification check, or allowlist enforcement. In an agent workflow, reports may contain sensitive internal data, so silent outbound transmission materially raises exfiltration risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · email_reporter.py (reported line 186)May include surrounding context.

python
env["EMAIL_SMTP_PASS"] = config.get("smtp_pass", "")
        env["EMAIL_USE_MSMTP"] = "true" if config.get("use_msmtp") else "false"
        
        result = subprocess.run(cmd, env=env, capture_output=True, text=True)
        
        if result.returncode == 0:
            print(f"✅ Report sent successfully: {attachment.name}")

Tainted flow: 'cmd' from os.getenv (line 169, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · email_reporter.py (reported line 186)May include surrounding context.

python
env["EMAIL_SMTP_PASS"] = config.get("smtp_pass", "")
        env["EMAIL_USE_MSMTP"] = "true" if config.get("use_msmtp") else "false"
        
        result = subprocess.run(cmd, env=env, capture_output=True, text=True)
        
        if result.returncode == 0:
            print(f"✅ Report sent successfully: {attachment.name}")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup wizard interactively collects SMTP credentials and persists them to a file in the user's home directory. Storing mail credentials on disk without access-control checks or secure storage makes credential theft easier for local attackers, malware, or other processes running under the same account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The setup wizard writes SMTP secrets to disk without a visible warning that sensitive credentials will be stored locally. Users may unknowingly create persistent plaintext secrets that can later be recovered from the home directory or backups.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The msmtp path builds a shell command with untrusted recipient input and executes it with shell=True. An attacker who controls to_addr can inject arbitrary shell metacharacters and achieve command execution, which is far more dangerous than the stated purpose of sending email.

Content

Scanner excerpt · send_attachment.py (reported line 117)May include surrounding context.

python
f.write(msg.as_bytes())
    
    cmd = f'cat {temp_file} | msmtp -t {to_addr}'
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    
    return result.returncode == 0

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes an email reporting tool that auto-converts Markdown to PDF before sending. In this implementation, the main send path only accepts an attachment path and sends the file as-is, with no Markdown parsing, PDF generation, or conversion logic anywhere in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the specified attachment file and message body to an external email recipient, which is a network transmission of local data. While it logs recipient and subject, it does not disclose the privacy/safety implication that the file's contents will be sent externally, and there is no confirmation prompt or explicit warning comment/docstring at the user entry point.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The QQ Mail setup step forces a Chinese-language instruction string in otherwise primarily English documentation. This can violate language or locale policy when no user opt-in or alternative language is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The QQ Mail setup section includes Chinese text in an otherwise English document, which can impose a language/locale assumption without user opt-in. The file does not indicate that the skill is region-specific or provide an alternative language choice for those instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The CSS forces a specific font stack centered on CJK Simplified Chinese fonts in the generated PDF. This is a natural-language/locale preference embedded in the skill without any user opt-in or documented justification, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.