Back to skill

Security audit

Apple Mail Search Safe (fruitmail)

Security checks for vulnerabilities and agentic risk

Overview

The skill’s email-search purpose is clear, but it relies on a globally installed, unpinned third-party npm CLI that can read local Apple Mail data.

Review the fruitmail package and publisher before installing, prefer an exact audited version or isolated install, avoid sudo, and remember that using this skill gives the installed CLI access to Apple Mail metadata and full email bodies on the local Mac.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 6 and 14–17
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Relevant Code:

yaml
metadata: {"clawdbot":{"emoji":"📧","requires":{"bins":["fruitmail"]},"install":[{"id":"node","kind":"node","package":"fruitmail","bins":["fruitmail"],"label":"Install fruitmail (npm)"}]}}
markdown
## Installation

```bash
npm install -g fruitmail
text

### Technical Analysis

The skill instructs users and supporting automation to install the latest version of the third-party `fruitmail` package from the npm registry. It does not specify an exact audited version, integrity hash, lockfile, or immutable artifact reference.

Because npm packages may define lifecycle scripts, package-controlled code can execute during installation with the privileges of the user running npm. The `-g` option also places the package in a global installation scope rather than isolating it to the project. The resulting CLI is then expected to access sensitive Apple Mail metadata and complete message bodies.

The available file does not prove that the current `fruitmail` package is malicious. The vulnerability is the unsafe dependency trust model: a future malicious release, registry compromise, publisher-account compromise, or package replacement could cause users to install code that was not present during this audit.

### Attack Path

1. An attacker compromises the npm publisher account, registry distribution path, or another component used to publish `fruitmail`.
2. The attacker publishes a malicious release under the expected package name.
3. A user or agent follows the skill instructions and runs `npm install -g fruitmail` without an exact version or integrity constraint.
4. npm downloads the attacker-controlled release and may execute its lifecycle scripts during installation.
5. The installed global CLI executes with the invok
...[truncated 1031 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin fruitmail to an exact version in both the metadata and installation command, for example fruitmail@X.Y.Z, after reviewing that release.
  2. Verify the package publisher, repository, release provenance, and npm integrity digest before recommending installation.
  3. Use a lockfile or an immutable, integrity-verified artifact so dependency resolution cannot silently change after review.
  4. Audit the selected package's source, transitive dependencies, and npm lifecycle scripts.
  5. Disable lifecycle scripts during installation where compatible, such as with npm install --ignore-scripts, and separately perform any required trusted setup.
  6. Prefer a project-local or isolated installation over npm install -g to reduce command-path exposure and simplify removal.
  7. Run the CLI without administrative privileges and grant only the macOS permissions required to read Mail data.
  8. Document the package version and integrity value that were actually audited, and establish a controlled review process before updating them.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.