Back to skill

Security audit

GoToEmail — 邮箱绑定

Security checks for vulnerabilities and agentic risk

Overview

This email skill does what it says, but it handles powerful mailbox credentials in a way users should review carefully before installing.

Review before installing. Use a disposable app password or authorization code where possible, avoid typing real mailbox secrets directly into the documented echo commands, rotate any credential already used that way, and be aware that reading a message may mark it as read by default. Only use trusted IMAP/SMTP hosts you intend to authenticate to.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Mailbox Credentials Exposed Through Shell Command Examples

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42, 48, 60, and 68
Vulnerability Type: Credentials embedded in shell command arguments
Risk Level: Medium

Vulnerable Code

bash
echo '{"email":"user@163.com","password":"authorization-code"}' | python scripts/test_connection.py
bash
echo '{"email":"user@corp.com","password":"pass","imap_host":"imap.corp.com","smtp_host":"smtp.corp.com"}' | python scripts/test_connection.py
bash
echo '{"email":"...","password":"...","imap_host":"imap.163.com","imap_port":993,"folder":"INBOX","limit":20,"unread_only":false}' | python scripts/list_emails.py
bash
echo '{"email":"...","password":"...","imap_host":"imap.163.com","uid":"1234","mark_as_read":true}' | python scripts/read_email.py
bash
echo '{"email":"...","password":"...","smtp_host":"smtp.163.com","smtp_port":465,"to":"recipient@example.com","subject":"subject","body":"message body"}' | python scripts/send_email.py

Technical Analysis

The scripts correctly read JSON from standard input, but the documented invocation pattern places the complete JSON document—including the mailbox authorization code, application password, or enterprise mailbox password—inside an echo command argument.

When users replace the placeholders with real credentials, the secret may be:

  • Persisted in interactive shell history.
  • Captured by terminal or session-recording systems.
  • Collected by command telemetry and audit logging.
  • Temporarily visible through local process inspection while echo is running.
  • Exposed in copied command transcripts, troubleshooting records, or automation logs.

This undermines the intended security benefit of accepting credentials through standard input. Mailbox application passwords and authorization codes can grant both IMAP and SMTP access and therefore must be handled as authentication secrets.

Attack Path

  1. A user follows the examples in SKILL.md.
  2. The user replaces the passwo ...[truncated 1429 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace command examples containing credential placeholders in shell arguments with an interactive launcher that reads secrets using Python's getpass.getpass() or an equivalent no-echo prompt.
  2. Pass the secret directly to the target process through a protected file descriptor or pipe without first placing it in a command argument.
  3. Support retrieving credentials from an operating-system keychain or managed secret store.
  4. If a temporary configuration file is unavoidable, create it with owner-only permissions, avoid predictable paths, and delete it immediately after use.
  5. Add an explicit warning that real passwords, authorization codes, and application passwords must never be entered directly into shell command lines.
  6. Document credential rotation and revocation procedures in case a secret has already been entered using the existing examples.
  7. Ensure wrappers and automation do not print the input JSON or include it in debug, CI, telemetry, or exception logs.
  8. Prefer a usage pattern such as an interactive wrapper:
python
import getpass
import json
import subprocess

email = input("Email: ").strip()
password = getpass.getpass("Authorization code or app password: ")

payload = {
    "email": email,
    "password": password,
}

subprocess.run(
    ["python", "scripts/test_connection.py"],
    input=json.dumps(payload),
    text=True,
    check=False,
)

This keeps the credential out of the shell command line and prevents terminal echo during entry.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broader mailbox-management skill that supports binding email accounts and both reading and sending mail, with provider-specific IMAP/SMTP configuration. However, this code chunk is narrowly focused on outbound SMTP sending only. It logs into an SMTP server and sends a message; there is no IMAP access, no mailbox reading, no account persistence/binding logic, and no broader mailbox management. While sending email is consistent with part of the description, the actual behavior of this chunk is materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is narrowly scoped to validating mailbox connectivity and authentication over IMAP/SMTP. This partially aligns with '绑定邮箱/添加邮箱/配置邮箱' because connection testing can support mailbox setup. However, the declared description also promises managing mail, reading mail, checking mail, and sending mail, none of which are present in this code chunk. There are no undeclared dangerous behaviors; the issue is that the description overstates the implemented functionality in this chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly instructs use of Python scripts that connect to external IMAP/SMTP servers, but the manifest does not declare any tool scope or permission boundary for network access. In a skill ecosystem, undeclared network capability weakens reviewability and user consent because the skill can transmit sensitive mailbox credentials and email content off-host without an explicit capability declaration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to provide highly sensitive email credentials and app passwords via shell commands piped through stdin, but gives no explicit warning about secret handling, storage, process history, or logging risks. In the context of an email-management skill, these credentials grant broad mailbox access, so poor secret-handling guidance can lead to account compromise, data exposure, or unauthorized email sending.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s user-facing documentation and error/output descriptions are entirely in Chinese, and the runtime messages also assume Chinese as the interaction language. This imposes a specific language/locale without any opt-in, alternative, or stated region-specific justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script defaults mark_as_read to true and then explicitly sets the \Seen flag, changing mailbox state unless the caller opts out. In an email-reading skill, silent state mutation can mislead users, hide unread messages, and alter audit/user workflow expectations, especially when the caller may assume a read-only fetch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code accepts a password field from stdin and uses it to authenticate to an external IMAP server, which is a sensitive-credential access and network transmission operation. Although the module docstring describes inputs, it does not warn the user that credentials will be sent to the mail server for authentication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language instructions and examples exclusively in Chinese, including the module description, input schema notes, and output descriptions. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code uses the provided email address and password to log into external IMAP and SMTP servers, which is a safety-relevant network operation involving sensitive credentials. While the module docstring describes the inputs, there is no explicit warning or confirmation that the script will transmit those credentials to remote mail servers for live authentication tests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses a single forced language throughout, beginning with the title on L01, and does not provide an opt-in, alternative language, or justification that the content is intended only for a Chinese-speaking or region-specific audience. Under the policy criteria, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The human-readable docstring and usage description are presented solely in Chinese, which imposes a specific language choice on users. Under the language policy, this should either offer language choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language instructions, input/output descriptions, and error text are presented exclusively in Chinese, with no indication that users may choose another language. This can violate language/locale policy when a skill forces a specific language without offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.