Back to skill

Security audit

QQMail Organizer

Security checks for vulnerabilities and agentic risk

Overview

This skill manages QQ Mail through disclosed IMAP/SMTP commands and includes clear dry-run and approval safeguards for risky mailbox changes.

Install only if you are comfortable granting an agent access to your QQ Mail authorization code and mailbox. Start with read-only JSON plans and dry-runs, review exact proposed actions before using --apply, and reserve permanent deletion for explicit, narrow requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes high-risk capabilities (environment access for credentials, file reads, shell execution, and networked email operations) but does not declare any explicit tool scope or permission boundaries in the skill manifest. That omission can cause a parent agent/runtime to grant broader access than necessary, weakening least-privilege controls and making accidental or unauthorized mailbox actions more likely.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/auto_archive.py (reported line 39)May include surrounding context.

python
if args.apply and not args.dry_run:
        cmd.append("--apply")

    raise SystemExit(subprocess.call(cmd))


if __name__ == "__main__":

Static analysis

No suspicious patterns detected.