Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md | `resend` | migration | `references/migrate-resend.md` |
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an operational Mailfully setup guide that makes disclosed, purpose-aligned code, email, and DNS changes with user confirmation gates.
Install this only if you want an agent to modify your app’s transactional email path. Review the proposed files, package changes, test send, DNS records, and any Cloudflare or Route 53 writes before approving them; keep real API keys out of chat and place them only in the intended local or hosting environment yourself.
Referenced artifact was not completely inspected
| `resend` | migration | `references/migrate-resend.md` |
Referenced artifact was not completely inspected
| `resend` | migration | `references/migrate-resend.md` |
Referenced artifact was not completely inspected
| `@sendgrid/mail`, `sendgrid` | migration | `references/migrate-sendgrid.md` |
Referenced artifact was not completely inspected
| `@sendgrid/mail`, `sendgrid` | migration | `references/migrate-sendgrid.md` |
Referenced artifact was not completely inspected
| `@sendgrid/mail`, `sendgrid` | migration | `references/migrate-sendgrid.md` |
Referenced artifact was not completely inspected
| `postmark` | migration | `references/migrate-postmark.md` |
Referenced artifact was not completely inspected
| `postmark` | migration | `references/migrate-postmark.md` |
Referenced artifact was not completely inspected
`, Symfony `MAILER_DSN`, or Django, Rails or Laravel set to SMTP | migration | `references/migrate-nodemailer.md` (a `MAILER_DSN` naming SendGrid or Postmark us
Referenced artifact was not completely inspected
`, Symfony `MAILER_DSN`, or Django, Rails or Laravel set to SMTP | migration | `references/migrate-nodemailer.md` (a `MAILER_DSN` naming SendGrid or Postmark us
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
import os
ENV_FILE = ".env" # the env file the app loads
def load_mailfully_key(path=ENV_FILE):
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
TypeScript project, save it as lib/mailfully-webhook.ts and type the parameters. It needs Node's
crypto and nothing else.
import { createHmac, timingSafeEqual } from "node:crypto";
The top-level description does not prominently warn that the skill may modify project files, install dependencies, send a test email, and guide DNS/domain changes. Because these actions have operational and security consequences, insufficient upfront disclosure can lead to users invoking the skill without informed consent.
The activation description uses broad triggers like choosing, switching, or cutting provider cost, which can cause the skill to activate during ordinary discussion rather than an explicit request to modify email infrastructure. In this skill, activation leads to code changes, dependency installation, test sends, and DNS preparation, so over-broad routing increases the chance of unintended high-impact actions.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Ground rules for every phase:
- Never ask the user to paste the key into the chat. Never read, print, grep or parse the env file or the key in shell.
If a key shows up in the conversation anyway, tell the user to revoke it and create a new one.
- The user pastes keys and secrets into the env file themselves. The only thing you write about a
key is the empty placeholder `MAILFULLY_API_KEY=` in `.env.example`. Never put a key on a command
The skill directs the agent to send an email via Mailfully and poll Mailfully's API with an authorization bearer token, which is an intentional external transmission of project-derived data to a third-party service. Even though the script uses test mode and avoids real inbox delivery, it still transmits message metadata and exercises live credentials, so this must be treated as a sensitive outbound action requiring explicit user consent.
Test mode needs no DNS and no verified domain, and it delivers to no real inbox.
4. Prints the returned `id` (`messageId` from the Nodemailer wrapper) and `status`. If the send returns
`status: "canceled"`, or raises on it (`MailfullySendError` with `type: "canceled"` from the wrapper, or the Django or Rails adapter's error), every recipient was suppressed: say so and stop; do not report success.
5. Polls `GET https://api.mailfully.com/v1/emails/<id>` with the same key (header
`Authorization: Bearer <key>`, read from the environment inside the script) every 5 s for up to 2
minutes, printing `last_event` each time. It keeps polling on `queued`, `sending`, `sent`, `held`,
`paused_hold` or `released`, stops on `delivered` (success), and stops on any other word as final and
The skill instructs use of npx tsx without pinning a version, which allows execution of whatever package version resolves at runtime. In an automated agent context this creates a supply-chain risk: behavior can change unexpectedly or a compromised upstream release could execute attacker-controlled code during the setup flow.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Find the zone, and show the user its name, id and status (active):
curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Find the zone, and show the user its name, id and status (active):
curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Find the zone, and show the user its name, id and status (active):
curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Find the zone, and show the user its name, id and status (active):
curl -s "https://api.cloudflare.com/client/v4/zones?name=<zone>" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
The wrapper documentation explicitly supports reading local files and fetching remote URLs for attachments, then sending the resulting content to Mailfully, but it does not consistently warn that this can transmit sensitive local data or trigger server-side requests to arbitrary destinations. In migration guidance used by an agent, that omission is security-relevant because developers may copy the pattern into contexts where attachment paths or URLs are user-controlled, leading to data exfiltration or SSRF.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
`postmark.Models.Message`, `postmark.Models.Attachment` or `postmark.Models.TemplatedMessage`.
- Calls: `client.sendEmail`, `client.sendEmailBatch`, `client.sendEmailWithTemplate`,
`client.sendEmailBatchWithTemplates`, and error checks against `postmark.Errors`.
- Raw API calls to `https://api.postmarkapp.com/email`, `/email/batch` or `/email/withTemplate`, with
an `X-Postmark-Server-Token` header (any language).
- Other stacks: a Postmark package in `requirements.txt`, `Gemfile` or `composer.json`
(`wildbit/postmark-php`), or a framework mail driver set to Postmark. A Django or Rails app moves to
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
`postmark.Models.Message`, `postmark.Models.Attachment` or `postmark.Models.TemplatedMessage`.
- Calls: `client.sendEmail`, `client.sendEmailBatch`, `client.sendEmailWithTemplate`,
`client.sendEmailBatchWithTemplates`, and error checks against `postmark.Errors`.
- Raw API calls to `https://api.postmarkapp.com/email`, `/email/batch` or `/email/withTemplate`, with
an `X-Postmark-Server-Token` header (any language).
- Other stacks: a Postmark package in `requirements.txt`, `Gemfile` or `composer.json`
(`wildbit/postmark-php`), or a framework mail driver set to Postmark. A Django or Rails app moves to
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def send_welcome(to):
response = requests.post(
"https://api.postmarkapp.com/email",
headers={"X-Postmark-Server-Token": os.environ["POSTMARK_SERVER_TOKEN"]},
json={
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def send_welcome(to):
response = requests.post(
"https://api.postmarkapp.com/email",
headers={"X-Postmark-Server-Token": os.environ["POSTMARK_SERVER_TOKEN"]},
json={
No suspicious patterns detected.