Back to skill

Security audit

email-manager-pop3

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a normal email reader/sender, but it includes an undocumented delete-email API and a risky no-TLS mail connection option.

Review before installing. Use only app-specific mailbox credentials, keep `use_ssl` enabled, and avoid exposing this skill to agents or callers that might invoke undocumented Python methods until deletion is removed or clearly documented with confirmation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
email_manager.py:129
Finding

Mailbox credentials and email data may be transmitted without TLS

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
email_manager.py:253
Finding

Undocumented public API permits destructive mailbox deletion

Content
View full analysis
bool: """ Mark the specified email for deletion Args: index: Email sequence number Returns: Whether deletion was successfully marked """ if not self.pop3_conn: self.connect_pop3() try: self.pop3_conn.dele(index) return True except Exception as e: raise RuntimeError(f'Deleting email failed: {str(e)}') ``` ### Technical Analysis The documented skill scope describes listing, counting, reading, and sending email, but the implementation also exposes a public `delete_mail()` method. This method directly issues the POP3 `DELE` command without confirmation, authorization checks, or target-message verification. Under POP3 semantics, `DELE` marks a message for deletion, and the deletion normally becomes effective when the session terminates successfully with `QUIT`. Because `disconnect_pop3()` calls `quit()`, a normal caller workflow can commit the removal. The method is not exposed by the included CLI, but any agent, integration, or Python caller able to instantiate `EmailManager` can invoke it. The destructive capability therefore exceeds the feature scope declared in the skill documentation. ### Attack Path 1. A caller or agent obtains access to the initialized `EmailManager` instance and its configured mailbox session. 2. The caller selects or supplies a POP3 message index. 3. The caller invokes `delete_mail(index)`. 4. The method sends the POP3 `DELE` command without requiring confirmation or checking whether deletion is authorized for the current task. 5. When the session ends successfully through `QUIT`, the server commits the deletion according to its POP3 behavior. ### Impact Assessment A caller with access ...[truncated 410 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose says the skill queries and sends email, but the detected behavior includes undeclared POP3 deletion and a CLI entrypoint. Undisclosed destructive behavior is dangerous because an agent or user may invoke the skill assuming read/send semantics while it can also remove messages or expose broader operational surfaces through command-line usage.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill declares no explicit tool scope or permissions even though it appears to require file-reading capability for loading local configuration containing email credentials. Missing scope declarations weakens reviewability and least-privilege controls, making it easier for an agent runtime to grant broader access than users expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata says it only queries and sends email, but the code also exposes a delete_mail capability that marks messages for deletion on the POP3 server. This hidden destructive behavior increases the risk that a caller or agent will invoke mailbox-deleting functionality without the user's informed consent or appropriate policy checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

delete_mail performs a destructive operation immediately with no confirmation, dry-run mode, undo, or higher-level safety gate. In an agent context, this can lead to accidental or prompt-induced deletion of emails, especially because POP3 deletions may be committed when the session ends and can permanently remove data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language comments and instructions are entirely in Chinese, with no indication that users may select another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module title and descriptions are written as Chinese-only user-facing text, including the main skill description and CLI usage strings, with no indication that users may choose another language. This can violate language/locale policy when a skill imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified as PyYAML>=6.0 without an upper bound or exact pin, which makes builds non-reproducible and allows different environments to resolve to different releases over time. In a security-sensitive skill that processes email and may parse configuration or message data, this increases supply-chain risk and can unexpectedly introduce vulnerable or incompatible versions.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
# Email Manager Skill Dependencies
PyYAML>=6.0

Unverifiable Dependency: PyYAML has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

PyYAML has a history of deserialization and input-validation issues, and because the manifest does not pin a specific version, it is impossible to verify whether the installed release includes fixes. This matters more in an email-management skill because email-related tooling often handles untrusted external content and configuration, so an unsafe or outdated YAML parser could become an attack surface if used on attacker-controlled data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.