Back to skill

Security audit

add-mailfully

Security checks for vulnerabilities and agentic risk

Overview

This skill is an operational Mailfully setup guide that makes disclosed, purpose-aligned code, email, and DNS changes with user confirmation gates.

Install this only if you want an agent to modify your app’s transactional email path. Review the proposed files, package changes, test send, DNS records, and any Cloudflare or Route 53 writes before approving them; keep real API keys out of chat and place them only in the intended local or hosting environment yourself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (43)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
| `resend` | migration | `references/migrate-resend.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 345)May include surrounding context.

md
| `resend` | migration | `references/migrate-resend.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
| `@sendgrid/mail`, `sendgrid` | migration | `references/migrate-sendgrid.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
| `@sendgrid/mail`, `sendgrid` | migration | `references/migrate-sendgrid.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
| `@sendgrid/mail`, `sendgrid` | migration | `references/migrate-sendgrid.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
| `postmark` | migration | `references/migrate-postmark.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

md
| `postmark` | migration | `references/migrate-postmark.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
`, Symfony `MAILER_DSN`, or Django, Rails or Laravel set to SMTP | migration | `references/migrate-nodemailer.md` (a `MAILER_DSN` naming SendGrid or Postmark us

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 348)May include surrounding context.

md
`, Symfony `MAILER_DSN`, or Django, Rails or Laravel set to SMTP | migration | `references/migrate-nodemailer.md` (a `MAILER_DSN` naming SendGrid or Postmark us

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-essentials.md (reported line 319)May include surrounding context.

python
import os

ENV_FILE = ".env"  # the env file the app loads


def load_mailfully_key(path=ENV_FILE):

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/webhooks.md (reported line 70)May include surrounding context.

TypeScript project, save it as lib/mailfully-webhook.ts and type the parameters. It needs Node's crypto and nothing else.

js
import { createHmac, timingSafeEqual } from "node:crypto";

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level description does not prominently warn that the skill may modify project files, install dependencies, send a test email, and guide DNS/domain changes. Because these actions have operational and security consequences, insufficient upfront disclosure can lead to users invoking the skill without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description uses broad triggers like choosing, switching, or cutting provider cost, which can cause the skill to activate during ordinary discussion rather than an explicit request to modify email infrastructure. In this skill, activation leads to code changes, dependency installation, test sends, and DNS preparation, so over-broad routing increases the chance of unintended high-impact actions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
Ground rules for every phase:

- Never ask the user to paste the key into the chat. Never read, print, grep or parse the env file or the key in shell.
  If a key shows up in the conversation anyway, tell the user to revoke it and create a new one.
- The user pastes keys and secrets into the env file themselves. The only thing you write about a
  key is the empty placeholder `MAILFULLY_API_KEY=` in `.env.example`. Never put a key on a command

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill directs the agent to send an email via Mailfully and poll Mailfully's API with an authorization bearer token, which is an intentional external transmission of project-derived data to a third-party service. Even though the script uses test mode and avoids real inbox delivery, it still transmits message metadata and exercises live credentials, so this must be treated as a sensitive outbound action requiring explicit user consent.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
Test mode needs no DNS and no verified domain, and it delivers to no real inbox.
4. Prints the returned `id` (`messageId` from the Nodemailer wrapper) and `status`. If the send returns
   `status: "canceled"`, or raises on it (`MailfullySendError` with `type: "canceled"` from the wrapper, or the Django or Rails adapter's error), every recipient was suppressed: say so and stop; do not report success.
5. Polls `GET https://api.mailfully.com/v1/emails/<id>` with the same key (header
   `Authorization: Bearer <key>`, read from the environment inside the script) every 5 s for up to 2
   minutes, printing `last_event` each time. It keeps polling on `queued`, `sending`, `sent`, `held`,
   `paused_hold` or `released`, stops on `delivered` (success), and stops on any other word as final and

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs use of npx tsx without pinning a version, which allows execution of whatever package version resolves at runtime. In an automated agent context this creates a supply-chain risk: behavior can change unexpectedly or a compromised upstream release could execute attacker-controlled code during the setup flow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/dns-providers.md (reported line 203)May include surrounding context.

  1. Find the zone, and show the user its name, id and status (active):

    bash
    curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
      -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/dns-providers.md (reported line 203)May include surrounding context.

  1. Find the zone, and show the user its name, id and status (active):

    bash
    curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
      -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/dns-providers.md (reported line 212)May include surrounding context.

  1. Find the zone, and show the user its name, id and status (active):

    bash
    curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
      -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/dns-providers.md (reported line 228)May include surrounding context.

  1. Find the zone, and show the user its name, id and status (active):

    bash
    curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
      -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The wrapper documentation explicitly supports reading local files and fetching remote URLs for attachments, then sending the resulting content to Mailfully, but it does not consistently warn that this can transmit sensitive local data or trigger server-side requests to arbitrary destinations. In migration guidance used by an agent, that omission is security-relevant because developers may copy the pattern into contexts where attachment paths or URLs are user-controlled, leading to data exfiltration or SSRF.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migrate-postmark.md (reported line 18)May include surrounding context.

md
`postmark.Models.Message`, `postmark.Models.Attachment` or `postmark.Models.TemplatedMessage`.
- Calls: `client.sendEmail`, `client.sendEmailBatch`, `client.sendEmailWithTemplate`,
  `client.sendEmailBatchWithTemplates`, and error checks against `postmark.Errors`.
- Raw API calls to `https://api.postmarkapp.com/email`, `/email/batch` or `/email/withTemplate`, with
  an `X-Postmark-Server-Token` header (any language).
- Other stacks: a Postmark package in `requirements.txt`, `Gemfile` or `composer.json`
  (`wildbit/postmark-php`), or a framework mail driver set to Postmark. A Django or Rails app moves to

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migrate-postmark.md (reported line 482)May include surrounding context.

md
`postmark.Models.Message`, `postmark.Models.Attachment` or `postmark.Models.TemplatedMessage`.
- Calls: `client.sendEmail`, `client.sendEmailBatch`, `client.sendEmailWithTemplate`,
  `client.sendEmailBatchWithTemplates`, and error checks against `postmark.Errors`.
- Raw API calls to `https://api.postmarkapp.com/email`, `/email/batch` or `/email/withTemplate`, with
  an `X-Postmark-Server-Token` header (any language).
- Other stacks: a Postmark package in `requirements.txt`, `Gemfile` or `composer.json`
  (`wildbit/postmark-php`), or a framework mail driver set to Postmark. A Django or Rails app moves to

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migrate-postmark.md (reported line 481)May include surrounding context.

md
def send_welcome(to):
    response = requests.post(
        "https://api.postmarkapp.com/email",
        headers={"X-Postmark-Server-Token": os.environ["POSTMARK_SERVER_TOKEN"]},
        json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/migrate-postmark.md (reported line 481)May include surrounding context.

md
def send_welcome(to):
    response = requests.post(
        "https://api.postmarkapp.com/email",
        headers={"X-Postmark-Server-Token": os.environ["POSTMARK_SERVER_TOKEN"]},
        json={

Static analysis

No suspicious patterns detected.