Back to skill

Security audit

Email Manager

Security checks for vulnerabilities and agentic risk

Overview

This email-management skill is mostly coherent, but it grants broad mailbox-changing, scheduling, persistent logging, and external notification behavior with insufficient opt-in and safety boundaries.

Review before installing. Only use this skill if you are comfortable with an agent automatically moving emails, creating standard folders, maintaining email-derived state, scanning sent history, changing scheduled email checks, and potentially sending sender/subject/summary details over SMS or WhatsApp when a phone tool is available. Prefer explicit opt-in for scheduling, Twilio alerts, permanent spam rules, and domain-wide blocking.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:80
Finding

Persistent Spam-Rule Poisoning Through Unverified Email Classification

Content
View full analysis
**Solicitor Rule**: A sender asking for a reply (e.g., "let me know if you're interested") does > NOT automatically create a WaitingReply item. If the email itself is a solicitation, it goes to > Spam regardless of how it's phrased. Move to `/Spam`. Add sender domain to spam list in state (unless it is a major legitimate service domain like gmail.com, outlook.com — add the full address instead). ``` The persistence of the resulting rule is reinforced at `SKILL.md`, line 265: ```markdown - Spam additions are **permanent** in state unless user removes them. ``` The persistent storage location is defined in `references/rules-and-state.md`, lines 29-39: ```markdown ## Spam Sender List > Individual email addresses or domains to always route to /Spam. > Never add broad domains like gmail.com or outlook.com — add specific addresses only for those. ``` # Format: address_or_domain | date_added | reason # Example: # noreply@sketchy-promo.com | 2024-01-15 | unsolicited marketing ``` ...[truncated 2455 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:78
Finding

Indirect Prompt-Injection Exposure in Automated Email Processing

Content
View full analysis
**Solicitor Rule**: A sender asking for a reply (e.g., "let me know if you're interested") does > NOT automatically create a WaitingReply item. If the email itself is a solicitation, it goes to > Spam regardless of how it's phrased. Move to `/Spam`. Add sender domain to spam list in state (unless it is a major legitimate service domain like gmail.com, outlook.com — add the full address instead). #### 3b. Approved Newsletter / Mailing List If sender is on the approved sender list: - Route to that sender's designated newsletter folder (e.g., `/NL_TechCrunch`). - If no folder exists yet for this sender, create one named `/NL_` and update the folder routing matrix. - Move email and continue. #### 3c. Important Email Flag as **Important** if ANY of the following are true (baseline — user can extend via rules): - Subject or body contains urgency language: "urgent", "asap", "time-sensitive", "deadline", " ...[truncated 3488 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger is so broad that the skill may activate on casual or ambiguous mentions of email and then perform state-changing actions such as moving messages, creating folders, updating logs, or scheduling recurring runs. Over-broad proactive activation increases the chance of unintended tool use and autonomous side effects without a clear user request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The visible description does not clearly warn that the skill will autonomously create folders, move mail, maintain persistent state, and run on a schedule. Users may invoke it expecting read-only assistance, while the skill actually performs durable mailbox and filesystem modifications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to modify scheduled jobs, which extends its effective authority beyond mailbox operations into persistent autonomous execution. That can be abused to create or alter recurring tasks without sufficiently explicit user consent, causing repeated mailbox changes or continued background processing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames this skill as an email attendant that works with an already-connected email MCP and focuses on inbox organization, replying, spam management, and reporting. The Notifications section adds a separate phone-messaging capability through Twilio/WhatsApp/SMS, which is not declared in the manifest and is not an obvious requirement for managing email itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill can transmit sender, subject, and summary details over WhatsApp/SMS but does not clearly disclose this in its user-facing description. That creates a privacy and confidentiality risk, especially for sensitive email content and for channels with weaker security or shared-device exposure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill persists and may disclose detailed plain-language logs of important emails and waiting-reply items, creating a secondary store of sensitive communication metadata and summaries. If the state file or downstream notification channel is exposed, private relationships, subjects, and activity patterns can be leaked beyond the mailbox itself.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The rolling daily report stores participants and subject lines across processed mail, building a long-lived metadata index of user communications. Even without message bodies, this creates meaningful surveillance and leakage risk if accessed by other tools, users, or compromised components.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file establishes persistent agent memory for email management and explicitly says it is read on every run and written at the end, but provides no user-facing notice, consent boundary, or retention controls for storing email-derived state. In an email-management context, persistent storage of inbox metadata, sender identities, and processing notes can expose sensitive relationship, behavioral, and communication data if users are unaware or if the state file is broadly accessible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to scan the Sent folder and maintain logs of outbound addresses, important events, senders, and subject lines, but does not warn the user or require approval for this collection. Because this is an email skill handling inherently sensitive communications, background monitoring and logging of message metadata increases privacy risk and could reveal contacts, priorities, and communication history beyond what the user expects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.