Back to skill

Security audit

Inbox Manager

Security checks for vulnerabilities and agentic risk

Overview

This Gmail inbox skill is understandable, but it needs review because it can keep long-lived Gmail access tokens and bulk-trash messages across accounts without documented safeguards.

Install only if you are comfortable granting Gmail read/modify access and storing refresh tokens locally. Before using it, require account-specific confirmation and a preview for any archive, label, or trash action, protect the secrets/inbox directory, and revoke Google OAuth access if a token may have been exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The documentation identifies a secrets directory containing shared OAuth client credentials and per-account refresh tokens, which are highly sensitive and enable persistent access to Gmail accounts if exposed. In a skill designed to manage multiple accounts from one project, compromise of these files could grant broad unauthorized mailbox access across accounts.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

text
secrets/inbox/
  client_secret.json            — OAuth 2.0 Desktop client credentials (shared)
  accounts.json                  — {"account@gmail.com": {"label": ..., "token_file": "token-..."}}
  token-account-at-gmail-dot-com.json  — per-account OAuth token

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents bulk trash operations against Gmail messages but provides no requirement for preview, confirmation, dry-run mode, account scoping, or recovery guidance. In a multi-account inbox management context, this increases the risk of accidental destructive actions at scale, including deletion of important messages or security notifications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.