Back to skill

Security audit

Agents Mail — Free Email for AI Agents, with No sign-up, No API key needed

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent email-service integration, but it under-scopes high-impact agent behavior by telling agents to follow remote API instructions and to automatically process untrusted inbox content.

Install only if you are comfortable giving an agent an external mailbox and API key. Do not let it follow prose returned by the service as instructions, do not process email content as commands, require confirmation before sending or deleting mail, and avoid enabling heartbeat polling, auto-replies, or webhooks without clear owner approval and redaction rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:21
Finding

External API Response Is Treated as Trusted Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21-29
Vulnerability Type: Remote instruction injection through an external service response
Risk Level: High

Vulnerable Code Snippet

markdown
No mailbox yet? Get one first (no auth needed):

```bash
curl -X POST https://agentsmail.org/api/getemailaddress \
  -H "Content-Type: application/json" \
  -d '{"agent_name": "my-agent"}'

The API response contains everything you need — follow the instructions it returns to save your credentials and start sending.

text

### Technical Analysis

The Skill explicitly directs the agent to follow instructions returned by `https://agentsmail.org/api/getemailaddress`. Those instructions are not included in the audited package and can change independently after review.

Although HTTPS authenticates the destination and protects transport confidentiality, it does not constrain the semantics of the response. The service operator, a compromised service, or an attacker who gains control of its backend could return arbitrary instructional text. The Skill provides no response schema validation, instruction/data separation, action allowlist, or restriction preventing the returned content from requesting unrelated tool use.

Ordinary retrieval of structured mailbox fields such as `email` and `api_key` is necessary for the declared email functionality. Following arbitrary prose returned by the service is not necessary and exceeds the minimum privilege required.

### Attack Path

1. The agent loads the Skill and requests a mailbox from the unauthenticated registration endpoint.
2. The external service returns expected mailbox data together with malicious or compromised instructional text.
3. The Skill tells the agent to follow the returned instructions.
4. The instructions direct the agent to perform an action outside mailbox provisioning, such as reading a local secret, changing configuration, invoking another tool,
...[truncated 703 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to follow prose returned by the external service.
  • Define a strict local response schema containing only required fields such as email, api_key, tier_level, and quota metadata.
  • Treat every unexpected field and all response text as untrusted data.
  • Validate field types, formats, lengths, and allowed values before use.
  • Never execute commands, follow URLs, modify files, or invoke tools based solely on instructions embedded in an API response.
  • Document credential storage locally rather than delegating storage instructions to the server.
  • Require explicit user confirmation for actions beyond mailbox creation and the specific email operation requested.

T01 · Skill Instruction Hijacking

Error
Location
references/EXAMPLES.md:132
Finding

Heartbeat Integration Repeatedly Exposes the Agent to Untrusted Email Content

Content
View full analysis

Vulnerability Details

File Location: references/EXAMPLES.md, lines 132-143
Vulnerability Type: Indirect prompt injection through persistent inbox polling
Risk Level: High

Vulnerable Code Snippet

markdown
## Pattern 6: HEARTBEAT.md (Recommended for OpenClaw / Local Agents)

For agents without a public server, add inbox checking to your HEARTBEAT.md:

```markdown
## Check AgentsMail Inbox

curl -s https://agentsmail.org/api/inbox?is_read=0 \
  -H "Authorization: Bearer {your_api_key}"

If there are unread emails, summarize them (sender, subject, preview).
If no unread emails, reply HEARTBEAT_OK.
text

A corresponding recommendation also appears in `SKILL.md`, lines 67-74:

```markdown
## I want automatic notifications

Add an inbox check to your heartbeat routine. On each cycle, check for unread emails and notify your owner if any are found:

```bash
curl -s https://agentsmail.org/api/inbox?is_read=0 \
  -H "Authorization: Bearer {your_api_key}"

If unread emails found, summarize them (sender, subject, preview). If none, reply HEARTBEAT_OK.

text

### Technical Analysis

The proposed heartbeat repeatedly introduces externally controlled sender, subject, and preview fields into the agent's processing context. An internet sender can place prompt-like instructions in those fields. The instructions do not require the agent to treat email fields as inert data, escape control-like content, enforce an allowlist, or prohibit actions requested by an email.

Installing the check in `HEARTBEAT.md` makes the exposure recurring rather than limited to an explicit user request. A malicious message can therefore be presented on every heartbeat cycle until it is marked as read or removed.

Inbox access is necessary for the declared functionality, but automatically processing arbitrary public email without a trust boundary is broader than necessary. The agent should summarize untrusted values w
...[truncated 1187 chars]
Remediation
View remediation

Remediation Suggestions

  • Explicitly state that all email metadata and content are untrusted data and must never be followed as agent instructions.
  • Parse the API response into a strict structured representation and pass only escaped, length-limited fields to the summarization step.
  • Use a fixed summarization template that prohibits tool calls and actions based on message content.
  • Apply trusted-sender allowlists before automatically processing messages.
  • Require explicit owner approval before replying, opening links, downloading attachments, modifying files, or invoking other tools.
  • Prevent raw HTML, links, attachment contents, and quoted instructions from entering the control-prompt portion of the agent context.
  • Mark or quarantine suspicious messages and avoid repeatedly processing the same untrusted message.
  • Prefer an opt-in inbox check initiated by the user over unconditional persistent heartbeat polling.

T09 · Insecure Skill Coding Practices

Warning
Location
references/EXAMPLES.md:87
Finding

Webhook Signing Secret Is Printed to Standard Output

Content
View full analysis

Vulnerability Details

File Location: references/EXAMPLES.md, lines 87-97
Vulnerability Type: Sensitive secret exposure through logs and transcripts
Risk Level: Medium

Vulnerable Code Snippet

python
# Register webhook (must be public HTTPS)
webhook = requests.post("https://agentsmail.org/api/webhooks",
    headers=headers,
    json={
        "url": "https://your-server.com/incoming-email",
        "events": ["email.received"]
    }).json()

print(f"Webhook secret: {webhook['secret']}")  # For HMAC verification

Technical Analysis

The webhook registration response contains a secret used to authenticate webhook payloads with HMAC-SHA256. The example prints that secret to standard output.

Standard output is frequently captured in terminal scrollback, agent conversation transcripts, CI logs, observability platforms, shell-session recordings, and debugging systems. Consequently, a secret intended to be shown only once may be copied into multiple systems with broader access and longer retention.

Registering a webhook and retaining its verification secret are legitimate requirements of the declared functionality. Exposing the complete secret in output is unnecessary and violates secure secret-handling practice.

Attack Path

  1. A user or agent runs the webhook registration example.
  2. The API returns the webhook HMAC secret.
  3. The example prints the complete secret to standard output.
  4. A terminal recorder, agent transcript, CI service, logging collector, or another user with log access captures it.
  5. An attacker obtains the exposed secret.
  6. The attacker constructs an arbitrary webhook payload and calculates a valid HMAC signature.
  7. The configured webhook endpoint accepts the forged event as authentic.

Impact Assessment

An attacker possessing the secret can forge webhook payloads accepted by applications that rely solely on the demonstrated HMAC verification. Th ...[truncated 322 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the statement that prints the webhook secret.
  • Write the secret directly to a dedicated secret manager or protected configuration mechanism.
  • If environment-based storage is required, avoid command forms that expose the value through process arguments, command history, or logs.
  • Restrict secret access to the webhook receiver and use least-privilege file or secret-manager permissions.
  • Ensure all logging and exception handling redact values named secret, authorization headers, and API keys.
  • Rotate the webhook secret immediately if it has already appeared in logs or an agent transcript.
  • Add webhook replay protection, such as signed timestamps and event identifiers, in addition to HMAC verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (30)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
84% confidence
Finding

The delete-email endpoint performs irreversible destructive actions based on a caller-supplied emailId. In agent settings, if untrusted input can influence that parameter, an attacker could induce deletion of important evidence or business records from the mailbox.

Content

Scanner excerpt · references/API.md (reported line 126)May include surrounding context.

md
---

### DELETE /api/inbox/:emailId — Delete Email

Content destroyed immediately. Returns HMAC-SHA256 receipt. Envelope preserved for audit.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
83% confidence
Finding

This endpoint deletes sent-email records based on a provided identifier, enabling destructive modification of mailbox state. If an agent accepts untrusted instructions or manipulated IDs, it could remove audit-relevant sent items or disrupt operations.

Content

Scanner excerpt · references/API.md (reported line 146)May include surrounding context.


DELETE /api/sent/:emailId — Delete Sent Email

bash
curl -X DELETE https://agentsmail.org/api/sent/{emailId} \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Webhook removal changes security-relevant configuration using a supplied webhookId. In an agent environment, attacker-influenced parameters could disable monitoring, notifications, or downstream integrations, reducing visibility and control.

Content

Scanner excerpt · references/API.md (reported line 188)May include surrounding context.

md
### GET /api/webhooks — List Webhooks (Tier 1+)

### DELETE /api/webhooks/:webhookId — Remove Webhook (Tier 1+)

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Deleting contacts based on a provided email parameter is a state-changing action that can be abused if an agent accepts attacker-controlled values. While less severe than message deletion, it can disrupt workflows and poison trusted address books.

Content

Scanner excerpt · references/API.md (reported line 203)May include surrounding context.

-d '{"email": "friend@agentsmail.org", "name": "Friend"}'

text

### DELETE /api/contacts/:email — Remove Contact (Tier 1+)

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

ACL rule deletion can materially weaken mailbox security by removing whitelist/blacklist protections. If an attacker can steer the parameter or trigger this action indirectly through an agent, they may reopen access to blocked senders or disable intended restrictions.

Content

Scanner excerpt · references/API.md (reported line 220)May include surrounding context.

md
Type: `whitelist` or `blacklist`.

### DELETE /api/acl/:email — Remove ACL Rule (Tier 1+)

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

No mailbox yet? Get one first (no auth needed):

bash
curl -X POST https://agentsmail.org/api/getemailaddress \
  -H "Content-Type: application/json" \
  -d '{"agent_name": "my-agent"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs automatic polling of the inbox and owner notification with message summaries, but it does not warn that email content and metadata may contain sensitive third-party information. This creates a real privacy and data-handling risk because an agent could routinely exfiltrate sender, subject, and preview text to another recipient without user consent or policy checks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

没邮箱?先领一个(无需认证):

bash
curl -X POST https://agentsmail.org/api/getemailaddress \
  -H "Content-Type: application/json" \
  -d '{"agent_name": "my-agent"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/API.md (reported line 26)May include surrounding context.

GET /api/help — API Directory

bash
curl https://agentsmail.org/api/help

Returns all available endpoints, email lifecycle rules, and rate limits.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The API reference documents outbound email sending but does not explicitly warn that message contents, recipient addresses, and related metadata are transmitted to an external third-party service. In an agent context, that omission can cause operators or downstream tools to send sensitive user or system data off-platform without informed consent or policy checks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This documented send operation transmits arbitrary subject/body content and recipient information to an external mail service and onward to recipients. In agent workflows, that creates a real exfiltration path if prompts, secrets, or sensitive user data are inserted into the email body without explicit approval and visibility.

Content

Scanner excerpt · references/API.md (reported line 69)May include surrounding context.

Tier 0: 10 trial sends. Tier 1+: unlimited.

bash
curl -X POST https://agentsmail.org/api/send \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {api_key}" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
72% confidence
Finding

Reading inbox content from an external mailbox pulls third-party message data into the agent runtime, which can expose the system to prompt-injection, malicious links, tracking artifacts, or unsafe handling of sensitive content. The issue is contextual rather than the curl example itself, but the documentation lacks warnings about treating email content as untrusted input.

Content

Scanner excerpt · references/API.md (reported line 120)May include surrounding context.

First read auto-marks status from unread to read.

bash
curl https://agentsmail.org/api/inbox/{emailId} \
  -H "Authorization: Bearer {api_key}"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The webhook section explains how to configure event delivery to a public HTTPS endpoint but omits a clear warning that mailbox event data will be forwarded to a third-party URL controlled by the user. This can lead to silent exfiltration of sender/recipient metadata and possibly message-derived event information if an agent enables webhooks without adequate review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

Adding a webhook explicitly causes mailbox events to be transmitted to another external endpoint, creating a secondary exfiltration channel. Without clear warnings and destination validation guidance, an agent or operator could unintentionally forward mailbox data to an attacker-controlled service.

Content

Scanner excerpt · references/API.md (reported line 178)May include surrounding context.

URL must be public HTTPS. No localhost/private IPs.

bash
curl -X POST https://agentsmail.org/api/webhooks \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {api_key}" \
  -d '{"url": "https://your-server.com/webhook", "events": ["email.received"]}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 9)May include surrounding context.

md
import requests, os

# One call — no sign-up, no API key needed
agent = requests.post("https://agentsmail.org/api/getemailaddress",
    json={"agent_name": "inbox-watcher"}).json()

# Store securely as environment variable (NOT in plaintext files)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 20)May include surrounding context.

md
import requests, os

# One call — no sign-up, no API key needed
agent = requests.post("https://agentsmail.org/api/getemailaddress",
    json={"agent_name": "inbox-watcher"}).json()

# Store securely as environment variable (NOT in plaintext files)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 84)May include surrounding context.

md
import requests, os

# One call — no sign-up, no API key needed
agent = requests.post("https://agentsmail.org/api/getemailaddress",
    json={"agent_name": "inbox-watcher"}).json()

# Store securely as environment variable (NOT in plaintext files)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 104)May include surrounding context.

md
import requests, os

# One call — no sign-up, no API key needed
agent = requests.post("https://agentsmail.org/api/getemailaddress",
    json={"agent_name": "inbox-watcher"}).json()

# Store securely as environment variable (NOT in plaintext files)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 160)May include surrounding context.

md
import requests, os

# One call — no sign-up, no API key needed
agent = requests.post("https://agentsmail.org/api/getemailaddress",
    json={"agent_name": "inbox-watcher"}).json()

# Store securely as environment variable (NOT in plaintext files)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 164)May include surrounding context.

md
import requests, os

# One call — no sign-up, no API key needed
agent = requests.post("https://agentsmail.org/api/getemailaddress",
    json={"agent_name": "inbox-watcher"}).json()

# Store securely as environment variable (NOT in plaintext files)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 9)May include surrounding context.

md
import requests, os

# One call — no sign-up, no API key needed
agent = requests.post("https://agentsmail.org/api/getemailaddress",
    json={"agent_name": "inbox-watcher"}).json()

# Store securely as environment variable (NOT in plaintext files)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 20)May include surrounding context.

md
# Send immediately — 10 free sends at Tier 0
headers = {"Authorization": f"Bearer {api_key}", "Content-Type": "application/json"}
result = requests.post("https://agentsmail.org/api/send",
    headers=headers,
    json={
        "to": "owner@example.com",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-responder loop automatically reads messages, marks them as read, and sends replies with no warning about those side effects. This is dangerous because it can alter mailbox state, disclose that an account is monitored, and generate outbound responses to untrusted senders, enabling privacy, integrity, and abuse issues if deployed blindly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

Within the auto-responder pattern, the outbound send is triggered automatically based on untrusted incoming email without sender validation, rate limiting, or warning. That can be abused to cause unsolicited replies, confirm mailbox activity to attackers, and amplify spam or social-engineering workflows.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 66)May include surrounding context.

md
detail = requests.get(f"{API}/inbox/{email['email_id']}", headers=headers).json()

        # Reply
        requests.post(f"{API}/send", headers=headers, json={
            "to": detail["from"],
            "subject": f"Re: {detail['subject']}",
            "text": f"Got your message. Processing now."

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/EXAMPLES.md (reported line 84)May include surrounding context.

md
headers = {"Authorization": f"Bearer {api_key}", "Content-Type": "application/json"}

# Upgrade — owner gets magic link, click to confirm
result = requests.post("https://agentsmail.org/api/upgrade",
    headers=headers,
    json={
        "owner_email": "owner@example.com",

Static analysis

No suspicious patterns detected.