Back to skill

Security audit

Mail

Security checks for vulnerabilities and agentic risk

Overview

This mail skill is purpose-aligned and disclosed, but users should treat its email and credential setup guidance carefully.

Install only if you are comfortable letting the agent read/search your email and prepare sends through himalaya or Apple Mail. Review every outgoing message before approving send, create or update Keychain credentials yourself when possible, and prefer a trusted pinned himalaya version over floating install commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Himalaya Installation via Homebrew

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- `himalaya` - IMAP/SMTP CLI (`brew install himalaya` or `cargo install himalaya`)

Technical Analysis

The installation guidance uses mutable package references without specifying a reviewed version, cryptographic checksum, signature, or other integrity-verification mechanism. Consequently, the code installed when a user follows this instruction can differ from the version assessed when the skill was reviewed.

This is security-sensitive because Himalaya operates on email and invokes configured credential-retrieval commands. Although no evidence indicates that the current package is malicious, compromise of the package source, maintainer account, formula, registry, or a future release could cause attacker-controlled code to execute under the invoking user's account.

Attack Path

  1. An attacker compromises an upstream Himalaya release channel, package maintainer account, or package source.
  2. The attacker publishes a malicious version under the expected package identity.
  3. A user follows the unpinned installation command documented by this skill.
  4. The package manager resolves and installs the current compromised version.
  5. When Himalaya is invoked, malicious code executes with the user's permissions and can attempt to access mail data, configuration files, and credential-command output available to that process.

Impact Assessment

Successful exploitation could provide code execution with the privileges of the user installing or running Himalaya. The affected scope could include the user's configured mailbox data, Himalaya configuration, accessible local files, and credentials exposed to the process through configured Keychain retrieval commands. The instructions do not request elevated privileges, so the demons ...[truncated 70 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin Himalaya to a specifically reviewed release rather than installing the latest available version.
  • Document the authoritative package source and the expected publisher or maintainer.
  • Prefer package signatures or published checksums and verify downloaded artifacts before installation where the package ecosystem permits it.
  • For Cargo installations, use a reviewed version and its lockfile, for example: cargo install himalaya --version <reviewed-version> --locked.
  • Establish a dependency-update process that reviews release provenance and security-relevant changes before updating the documented version.

T08 · Insecure Dependencies

Warning
Location
himalaya.md:6
Finding

Unpinned Himalaya Installation Commands in CLI Setup Guide

Content
View full analysis

Vulnerability Details

File Location: himalaya.md, lines 6-9
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

bash
brew install himalaya
# or
cargo install himalaya

Technical Analysis

Both installation commands resolve the current package version at installation time. Neither command supplies a version constraint, uses a lockfile, nor verifies a checksum or signature. This creates a supply-chain trust gap: the executable ultimately run by the skill may not be the same artifact that was previously reviewed.

The Cargo command is additionally missing the --locked option, so dependency resolution may use dependency versions different from those recorded and tested by the upstream project. The audit found no evidence that the present Himalaya package or its dependencies are malicious; the risk arises from mutable, insufficiently verified future installation inputs.

Attack Path

  1. An attacker gains control of an applicable package publication channel, maintainer account, formula, package artifact, or transitive dependency.
  2. A compromised release is made available through Homebrew or Cargo.
  3. A user executes one of the documented installation commands.
  4. The package manager selects the compromised current version and, for Cargo, may resolve mutable dependency versions.
  5. The resulting binary executes as the user when email operations are performed.
  6. Malicious code can attempt to read accessible mail content, local configuration, and secrets made available through credential-retrieval commands, or perform other actions allowed to the user account.

Impact Assessment

Exploitation could lead to arbitrary code execution under the invoking user's privileges. Because the installed program is intended to access IMAP/SMTP accounts and retrieve passwords through configured commands, compromise could expose email contents, a ...[truncated 206 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace floating installation instructions with a specific, reviewed Himalaya release.
  • For Cargo, use cargo install himalaya --version <reviewed-version> --locked.
  • For Homebrew, document a trusted, versioned formula or another reproducible installation method where practical.
  • Verify package signatures or checksums against an authenticated upstream source before installation.
  • Record the expected artifact digest and package provenance in the setup guide.
  • Review and test upgrades before changing the pinned version, including changes to transitive dependencies.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes email operations with secure credential handling, which justifies using stored credentials, but line L69 instructs creating or modifying Keychain entries via security add-internet-password. That is a credential-management capability beyond simply using configured credentials for mail operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.