Back to skill

Security audit

Snail Mail

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local operator inbox with disclosed local storage and no network behavior, but users should treat stored and rendered messages as potentially sensitive.

Install only if you want agents to keep a local inbox of operational notes. Keep the workspace private, avoid storing secrets or credentials in messages, and be cautious rendering untrusted content to Slack or Discord because formatting and mentions may not be escaped.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/inbox.js:212
Finding

Unescaped User-Controlled Content in Markdown Rendering

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/inbox.js:27
Finding

Predictable Temporary File Allows Symlink-Based File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/inbox.js:19
Finding

Potentially Sensitive Inbox Data Uses Umask-Dependent Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger guidance says the operator asking to see their inbox or saying 'inbox', 'messages', or 'check inbox' should cause the skill to run. Terms like 'messages' are overly generic and can be invoked accidentally during ordinary conversation, causing unintended data disclosure or stateful actions in the wrong context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.