Back to skill

Security audit

Jmail World - Search Epstein Files, E-Mails & Messages

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its public-archive research purpose, but its bundled shell script has under-disclosed local file writes and concrete unsafe cache/query handling risks.

Review before installing. Use it only if you are comfortable running bundled shell scripts that contact jmail.world/data.jmail.world/assets.getkino.com, cache public datasets locally, and save downloaded files. Avoid running it with elevated privileges, use a private working directory for outputs, and treat downloaded PDFs/images and cached Parquet files as untrusted content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/jmail-duckdb.sh:169
Finding

Second-Order SQL Injection Through an Untrusted Dataset Value

Content
View full analysis
/dev/null | head -1) if [[ -n "$RESOLVED_SLUG" ]]; then FROM_FILTER="AND m.conversation_slug = '${RESOLVED_SLUG}'" echo " (filtered to: ${RESOLVED_SLUG})" else echo " ⚠️ No conversation found for '${FROM_NAME}', searching all" FROM_FILTER="" fi run_query " SELECT c.name as conversation, m.sender, m.text, m.time FROM read_parquet('${MSGS}') m JOIN read_parquet('${CONVOS}') c ON m.conversation_slug = c.slug WHERE m.text ILIKE '%${QUERY}%' ${FROM_FILTER} ORDER BY m.timestamp LIMIT 50; " ``` ### Technical Analysis `FROM_NAME` is passed through the script's sanitizer before use, but `RESOLVED_SLUG` is obtained from `imessage_conversations.parquet`, a remotely downloaded dataset. The returned slug is then interpolated directly into a second SQL statement without validation, escaping, or parameter binding. This is a second-order SQL injection: the dangerous value does not come directly from the command-line argument. Instead, attacker-controlled SQL syntax can be stored in the dataset, selected by the first query, and executed when the result is incorporated into the subsequent query. For example, a malicious slug containing a quote followed by additional DuckDB SQL could terminate the `conversation_slug` string literal and alter the second command. The use of `head -1` limits the result to one line but does not make the value safe for SQL interpolation. ### Attack Path 1. An attacker compromises the remote Parquet source, controls an upstream dataset-generation process, or causes the local cache to contain a malicious `imessage_conversations.parquet`. 2. The attacker inserts a co ...[truncated 1523 chars]
Remediation
View remediation
&2 exit 1 fi ``` 3. Prefer DuckDB parameter binding or a safely generated SQL literal instead of direct string interpolation. 4. Avoid constructing an SQL fragment in `FROM_FILTER`. Build separate fixed query forms for filtered and unfiltered searches. 5. Reject multiline, malformed, or ambiguous CSV output before using it in another command. 6. Where supported, restrict DuckDB external access and disable unneeded extension installation or loading. 7. Verify downloaded datasets using trusted checksums or signatures before querying them. 8. Update the security documentation so that it accurately reflects the trust boundary around remotely sourced Parquet content. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/jmail-duckdb.sh:71
Finding

Predictable Shared Temporary Cache Enables Symlink Overwrite and Cache Poisoning

Content
View full analysis
&2 exit 1 fi local local_path="${CACHE_DIR}/${name}" # Re-download if older than 24 hours or doesn't exist if [[ ! -f "$local_path" ]] || [[ $(find "$local_path" -mmin +1440 2>/dev/null) ]]; then echo "📥 Downloading ${name}..." >&2 curl -fsSL "${BASE}/${name}" -o "${local_path}.tmp" mv "${local_path}.tmp" "$local_path" fi echo "$local_path" } ``` ### Technical Analysis The script stores datasets in the fixed, globally predictable path `/tmp/jmail-cache`. It uses `mkdir -p` but does not verify that the existing path is a real directory, that it is owned by the invoking user, or that its permissions prevent modification by other local users. Downloads are also written to predictable names such as: ```text /tmp/jmail-cache/emails-slim.parquet.tmp ``` `curl -o` follows symbolic links. If another local user pre-creates the cache directory and a symbolic link at the expected temporary pathname, a subsequent download can overwrite a file writable by the victim. The final `mv` operation also does not verify the file type or ownership. Separately, an attacker who can pre-create or modify a cache entry can place a malicious Parquet file at the expected final pathname. The script trusts an existing cache file for up to 24 hours without validating its origin, checksum, ownership, or integrity. ### Attack Path #### Symlink overwrite 1. Before ...[truncated 1714 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description claims use of the official jmail.world data API, but the content also describes remote downloads from an additional external host and local PDF/image extraction and saving. This mismatch is dangerous because users and policy engines may approve the skill under a narrower trust model than its actual behavior, enabling unexpected data transfer and filesystem modification.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description claims use of the official jmail.world data API, but the content also describes remote downloads from an additional external host and local PDF/image extraction and saving. This mismatch is dangerous because users and policy engines may approve the skill under a narrower trust model than its actual behavior, enabling unexpected data transfer and filesystem modification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises and documents capabilities that rely on shell execution, network access, and local file operations, but it does not declare any explicit tool scope or allowed-tools boundary. That increases risk because a host agent may grant broader capabilities than users expect, reducing visibility and policy enforcement around external access and filesystem writes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes downloading remote documents and photos into local directories without a clear warning that it writes files and fetches untrusted external content. This is risky because users may unknowingly persist potentially sensitive, illegal, or malicious files locally, increasing exposure to disk misuse and downstream processing hazards.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation claims there are no writes, but the skill explicitly supports downloading and saving files to local output directories. This is dangerous because users may run the skill under the assumption it is read-only, when it can modify the local filesystem and store untrusted remote content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation claims there are no writes, but the skill explicitly supports downloading and saving files to local output directories. This is dangerous because users may run the skill under the assumption it is read-only, when it can modify the local filesystem and store untrusted remote content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a skill for searching and analyzing the jmail.world archive via its official Data API, with DuckDB/Parquet queries and file downloads. This script goes further by downloading datasets into a local cache and writing requested assets to arbitrary local output directories, making it a local content acquisition tool in addition to a search/analysis interface.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 9)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 91)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 96)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 102)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 108)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 109)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 115)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 120)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 125)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 134)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 135)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 136)May include surrounding context.

md
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/jmail-duckdb.sh (reported line 74)May include surrounding context.

sh
CACHE_DIR="/tmp/jmail-cache"
mkdir -p "$CACHE_DIR"

BASE="https://data.jmail.world/v1"

# Download a parquet file if not cached (or if older than 24h)
ensure_cached() {

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata says the archive is accessed via jmail.world's official Data API, but this code downloads files directly from a separate third-party host, assets.getkino.com. That expands the trust boundary and can expose users to unreviewed or substituted content, especially because the downloaded files are then saved locally and may be processed further.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.