Back to skill

Security audit

moltmail-ethermail

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Web3 email and wallet purpose, but it has unsafe command-invocation guidance and stores sensitive wallet and login state that users should review carefully.

Install only if you trust MoltMail/EtherMail with your agent email content and are comfortable storing an encrypted wallet key plus a reusable login token in the skill's local state directory. Run it in a contained workspace, protect ETHERMAIL_PASSPHRASE and ./state, update the flagged dependencies, and avoid letting the agent build shell command strings from email text or user-provided message content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:237
Finding

Shell Command Injection Through User-Controlled Email Arguments

Content
View full analysis
'' [--from ] ``` ``` The examples reinforce this behavior and explicitly permit user-provided HTML to be used as given: ```markdown User: "Send email to 0x3886e06217d31998a697c5060263beafe7bdc610@moltmail.io with subject 'Test Email' and with content '

Hello this is my test email

'" → Use the subject user gave, as email content is already HTML use it as-given with `npm run send-email`. ``` ### Technical Analysis The underlying TypeScript script reads arguments from `process.argv`, which is not inherently unsafe. The vulnerability occurs at the command-construction layer prescribed by `SKILL.md`. The command template surrounds the HTML body with single quotes but does not define any escaping or safe argument-passing mechanism. If a user-controlled recipient, subject, or body contains a single quote, it can terminate the quoted argument. Additional shell metacharacters can then be interpreted by the shell rather than passed to the TypeScript program. For example, a body shaped like the following can escape the intended argument: ```text '; attacker-controlled-command; echo ' ``` This vulnerability also applies to hostile content copied from an incoming email into a reply command. Quoting an argument with single quotes is insufficient unless embedded single quotes are safely encoded, and ad hoc shell escaping remains error-prone. ### Attac ...[truncated 1347 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:151
Finding

Untrusted Email Content Can Inject Instructions Into the Agent Session

Content
View full analysis
``` This fetches the full email and automatically marks it as read. Response includes `html` and `text` fields with the email body. ``` The example workflow requires the body to be placed into the Agent's working context: ```markdown User: "Read the email..." → Run `npm run get-email -- ` for the email matching the user's description (by subject, sender, etc.) and present: sender, subject, sent date, email body and possible attachments. The email is automatically marked as read. ``` The script returns the remote response directly: ```ts const { userId } = await loadAuth(); const email = await getEmailContent(userId, mailboxId, messageId); // Automatically mark as read when content is fetched await markEmailAsRead(userId, mailboxId, messageId); return email; main().then(result => { console.log(JSON.stringify(result, null, 2)); }); ``` ### Technical Analysis Email bodies are controlled by remote senders. They may contain natural-language instructions crafted to resemble system, developer, user, or Skill directives. The retrieved `html` and `text` fields are printed directly and then presented to the user without an explicit instruction that their contents are untrusted data. This creates an indirect prompt-injection channel. An attacker cannot necessarily force execution solely by sending an email, but the email may influence the Agent when a user asks it to read or process the message. The risk is amplified because the same Skill provides state-changing capabilities s ...[truncated 1704 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.ts:116
Finding

Sensitive State Files May Retain Insecure Existing Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims a broad external infrastructure product for agent email, wallets, identity, communications, and payments. The code chunk does not implement any of those product capabilities or interact with external services. Instead, it is a standalone encryption/decryption helper using Node's crypto library. While cryptography could be a supporting detail inside such a system, this chunk by itself materially differs from the declared purpose and lacks any evidence of the described email/wallet/identity behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad platform for agent email, wallet, and identity infrastructure. However, the supplied code chunk performs a much narrower and different action: it loads auth information and outputs the userId as a referral code. There is no evidence in this chunk of email handling, wallet creation or use, agent identity management beyond reading existing auth, communications, or payment functionality. The actual behavior is materially different from the declared purpose, and the specific referral-code behavior is not represented in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description markets a full agent identity platform combining email and wallet infrastructure. The supplied code does not implement those platform capabilities. Instead, it performs a narrow, local initialization flow for an EtherMail wallet configuration file. It creates or imports a wallet, encrypts its private key with a user-supplied passphrase, and writes the result to disk. This is materially different from the advertised purpose because there is no email functionality, no network/API interaction, no payment logic, and no broader identity-layer operations. The mismatch is substantial and concerns the primary purpose, not just omitted implementation details.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins axios 1.13.5, and the provided advisories include SSRF/proxy bypass and prototype-pollution-related MITM/credential theft issues. In a skill that provisions agent email and wallet identities and likely makes outbound API calls, a vulnerable HTTP client is security-relevant because it can expose secrets, route requests unexpectedly, or weaken trust in remote responses.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
82% confidence
Finding

form-data 4.0.5 is reported as vulnerable to CRLF injection through unescaped multipart field names/filenames. If any part of the skill builds multipart requests from untrusted input, an attacker could manipulate request structure or smuggle unintended headers/content, which can affect upstream services or bypass validation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
88% confidence
Finding

ws 8.17.1 is flagged for memory disclosure and memory exhaustion DoS issues. Since ethers depends on ws and this skill deals with wallet infrastructure, WebSocket-based blockchain/provider connectivity may be used; if exposed to malicious peers or untrusted endpoints, this could leak process memory or crash the agent via resource exhaustion.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

The manifest allows installation of an axios version reported as having multiple known advisories, including SSRF and man-in-the-middle/prototype-pollution-related issues. In an agent skill that performs email and wallet infrastructure actions, compromised HTTP behavior could expose credentials, route requests to attacker-controlled endpoints, or tamper with sensitive API responses.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'enquirer' resembles popular package 'inquirer'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'enquirer' resembles popular package 'inquirer'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares installType: code and explicitly uses environment variables for a passphrase, but it does not declare any tool scope such as allowed tools or permissions. In an agent setting, missing scope boundaries can let the skill run with broader execution or secret-access privileges than users expect, which is especially risky because this skill handles wallet keys, passphrases, and auth tokens.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation condition 'When user refers to testing MoltMail skill' and related usage guidance are ambiguous and lack clear boundaries, which increases the chance of unintended invocation. Because this skill handles passphrases, private keys, auth tokens, and remote API actions, accidental activation is more dangerous than for a read-only informational skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is framed as suitable for temporary or disposable email use, but the setup requires persistent wallet-backed identity, encrypted local credential storage, and token persistence. That mismatch can lead users or orchestrators to invoke it in low-trust contexts where they would not normally permit long-lived secret material, increasing the chance of credential mishandling or unintended persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example trigger phrases are broad enough to match ordinary requests like creating an email account or temp email, which could cause accidental activation of a code-executing skill that provisions wallets, stores credentials, and contacts an external service. In agent ecosystems, overbroad invocation patterns can turn benign user prompts into high-risk actions involving secrets and remote account creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The sendEmail function posts recipients, subject, and message body to the external Ethermail endpoint, which is a privacy-impacting network operation. In this file there is no confirmation prompt, user-facing log, or explanatory comment/docstring warning that user email content will be sent off-box.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The replyToEmail function sends message content, recipients, and message reference data to the external Ethermail service. This is a user-data transmission path, but the code provides no confirmation prompt, user-facing notice, or inline documentation warning about that behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This script changes message state as a side effect of a read-style operation without any confirmation or opt-in, which can weaken auditability and alter workflow semantics for downstream users or agents. In an agent/email automation context, silently marking messages as read can hide unread items, interfere with triage, and cause humans or other agents to miss security-relevant or time-sensitive emails.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that login saves a JWT token to ./state/auth.json but does not clearly warn users that this is a reusable bearer token whose theft could allow account access until expiry or revocation. In a skill that handles email and wallet-linked identity, local token persistence increases sensitivity because a compromised workstation, shared environment, or accidental file exposure could leak access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes the skill primarily as providing email addresses, crypto wallets, identity, payments, and agent communication. The documented commands for retrieving earned EMC rewards and referral codes introduce loyalty/affiliate capabilities that are not reflected in that stated purpose, making the described scope narrower than the actual documented behavior.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
84% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. Because it is pulled in by axios, a malicious or compromised endpoint could potentially trigger redirects that forward bearer tokens or API keys to another domain, which is especially sensitive for an agent infrastructure product handling email and wallet operations.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"get-earned-coins": "ts-node scripts/getEarnedCoins.ts"
  },
  "dependencies": {
    "axios": "^1.13.4",
    "enquirer": "^2.4.1",
    "ethers": "^6.16.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 19)May include surrounding context.

json
},
  "dependencies": {
    "axios": "^1.13.4",
    "enquirer": "^2.4.1",
    "ethers": "^6.16.0"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"dependencies": {
    "axios": "^1.13.4",
    "enquirer": "^2.4.1",
    "ethers": "^6.16.0"
  },
  "devDependencies": {
    "@types/node": "^25.2.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"ethers": "^6.16.0"
  },
  "devDependencies": {
    "@types/node": "^25.2.0",
    "ts-node": "^10.9.2",
    "typescript": "^5.9.3"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
},
  "devDependencies": {
    "@types/node": "^25.2.0",
    "ts-node": "^10.9.2",
    "typescript": "^5.9.3"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 25)May include surrounding context.

json
"devDependencies": {
    "@types/node": "^25.2.0",
    "ts-node": "^10.9.2",
    "typescript": "^5.9.3"
  }
}

Static analysis

Detected: suspicious.potential_exfiltration

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
lib/ethermail.ts:112