Back to skill

Security audit

Email163 Sender

Security checks for vulnerabilities and agentic risk

Overview

This is a real 163 email-sending skill, but it needs Review because it disables mail-server certificate checks and silently stores sensitive send-history metadata.

Review carefully before installing or using. Do not use it for sensitive email until TLS certificate validation is restored, and assume recipients, subjects, cc/bcc, and send timestamps may be saved locally in the workspace history file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/send_email.py:156
Finding

SMTP TLS Certificate Validation Is Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/send_email.py, lines 156–161
Vulnerability Type: Improper TLS certificate validation
Risk Level: High

Vulnerable Code

python
context = ssl.create_default_context()
context.check_hostname = False
context.verify_mode = ssl.CERT_NONE

with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT, context=context) as server:
    server.login(from_email, auth_code)
    server.sendmail(from_email, all_recipients, msg.as_string())

Technical Analysis

The code creates a TLS context but then explicitly disables hostname verification and certificate-chain validation. Consequently, the client encrypts its connection without authenticating that the remote endpoint is the legitimate smtp.163.com server.

An attacker who can intercept or redirect network traffic can present an arbitrary certificate, and the client will accept it. The application then transmits the sender address, SMTP authorization code, recipient information, message content, and attachments through the attacker-controlled endpoint.

Attack Path

  1. An attacker obtains a network interception position or manipulates DNS/routing for smtp.163.com.
  2. The attacker redirects the SMTP connection to a server under their control.
  3. The malicious server presents an untrusted certificate or a certificate issued for a different hostname.
  4. The client accepts that certificate because hostname checking and certificate validation are disabled.
  5. The client submits the mailbox address and SMTP authorization code to the malicious endpoint.
  6. The attacker captures the credentials and email data, and may proxy or alter the SMTP exchange to reduce the chance of detection.
  7. The stolen authorization code may subsequently be used to access SMTP functionality and send email as the victim, subject to the mailbox provider's authorization scope and controls.

Impact Assessment

Successful exploitation c ...[truncated 523 chars]

Remediation
View remediation

Remediation Suggestions

Preserve Python's secure TLS defaults and remove both assignments that disable validation:

python
context = ssl.create_default_context()

with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT, context=context) as server:
    server.login(from_email, auth_code)
    server.sendmail(from_email, all_recipients, msg.as_string())

Additionally:

  • Allow certificate or hostname validation failures to terminate transmission.
  • Do not introduce an insecure fallback that retries with validation disabled.
  • Use the operating system's maintained CA trust store, or explicitly configure a trusted CA bundle when required by the deployment environment.
  • Add an integration test verifying that expired, self-signed, untrusted, and hostname-mismatched certificates are rejected.
  • Rotate the SMTP authorization code if the application has previously operated over an untrusted network while certificate validation was disabled.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill uses sensitive capabilities implied by its documentation and examples, including reading environment variables for SMTP credentials and reading local files for attachments, but it does not declare any explicit tool scope or permission boundaries. This increases the risk of overbroad access and makes it harder for a host agent or reviewer to enforce least privilege, especially in a skill that can transmit local content externally via email.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description says to use the skill whenever a user needs to send email, which is very broad and can overlap with routine requests that may contain sensitive content. Broad invocation criteria increase the chance that an agent activates an exfiltration-capable skill in contexts where the user did not intend external transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation encourages sending email bodies, HTML, and attachments but does not warn that these may contain sensitive local or user data that will be transmitted to external recipients. In the context of an email skill, omission of a data-transmission warning is more dangerous because the core function is outbound exfiltration of content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is presented as an email-sending tool, but the documentation also exposes local history inspection and deletion features. Hidden or under-emphasized state-management behaviors can surprise users, expose metadata about prior communications, or allow destruction of audit/history data without clear consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persistently stores sent-email metadata, including recipients, cc, bcc, subject, sender, and timestamps, in a workspace-local JSON file. For a skill described only as an email sender, this creates an undeclared data-retention surface that can leak sensitive communication metadata to other local users, processes, or downstream tooling with workspace access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

After sending mail, the tool silently writes sensitive metadata to disk without any user-facing notice or consent. This is dangerous because email subjects, recipients, and especially bcc relationships may be confidential, and local persistence can violate user expectations and organizational data-handling requirements.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI exposes additional management functions such as listing sent emails, querying status by ID, and clearing history, which goes beyond the advertised purpose of only sending email. While not inherently malicious, these extra capabilities increase the attack surface around previously stored metadata and can expose sensitive information to anyone able to invoke the tool locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation mentions a clear-history option without warning that the action may be irreversible or may remove operational/audit records. While lower severity than outbound transmission issues, silent deletion of history can impair accountability and user recovery.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring and CLI-facing descriptions/messages are written in Chinese only, and the tool does not provide any user opt-in or language selection. This creates a natural-language locale policy issue because the skill imposes a specific language on all users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.