T09 · Insecure Skill Coding Practices
- Location
email_manager.py:129- Finding
Mailbox credentials and email data may be transmitted without TLS
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a normal email reader/sender, but it includes an undocumented delete-email API and a risky no-TLS mail connection option.
Review before installing. Use only app-specific mailbox credentials, keep `use_ssl` enabled, and avoid exposing this skill to agents or callers that might invoke undocumented Python methods until deletion is removed or clearly documented with confirmation.
email_manager.py:129Mailbox credentials and email data may be transmitted without TLS
email_manager.py:253Undocumented public API permits destructive mailbox deletion
The declared purpose says the skill queries and sends email, but the detected behavior includes undeclared POP3 deletion and a CLI entrypoint. Undisclosed destructive behavior is dangerous because an agent or user may invoke the skill assuming read/send semantics while it can also remove messages or expose broader operational surfaces through command-line usage.
The skill declares no explicit tool scope or permissions even though it appears to require file-reading capability for loading local configuration containing email credentials. Missing scope declarations weakens reviewability and least-privilege controls, making it easier for an agent runtime to grant broader access than users expect.
The skill metadata says it only queries and sends email, but the code also exposes a delete_mail capability that marks messages for deletion on the POP3 server. This hidden destructive behavior increases the risk that a caller or agent will invoke mailbox-deleting functionality without the user's informed consent or appropriate policy checks.
delete_mail performs a destructive operation immediately with no confirmation, dry-run mode, undo, or higher-level safety gate. In an agent context, this can lead to accidental or prompt-induced deletion of emails, especially because POP3 deletions may be committed when the session ends and can permanently remove data.
The natural-language comments and instructions are entirely in Chinese, with no indication that users may select another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.
The module title and descriptions are written as Chinese-only user-facing text, including the main skill description and CLI usage strings, with no indication that users may choose another language. This can violate language/locale policy when a skill imposes a specific language without opt-in or documented justification.
The dependency is specified as PyYAML>=6.0 without an upper bound or exact pin, which makes builds non-reproducible and allows different environments to resolve to different releases over time. In a security-sensitive skill that processes email and may parse configuration or message data, this increases supply-chain risk and can unexpectedly introduce vulnerable or incompatible versions.
# Email Manager Skill Dependencies
PyYAML>=6.0
PyYAML has a history of deserialization and input-validation issues, and because the manifest does not pin a specific version, it is impossible to verify whether the installed release includes fixes. This matters more in an email-management skill because email-related tooling often handles untrusted external content and configuration, so an unsafe or outdated YAML parser could become an attack surface if used on attacker-controlled data.
No suspicious patterns detected.