Back to skill

Security audit

Robotomail

Security checks for vulnerabilities and agentic risk

Overview

Robotomail is a coherent email-integration skill, but it gives an agent broad real-mailbox authority without enough user-control and privacy warnings.

Install only if you intend to let an agent use Robotomail for real email. Prefer a mailbox-scoped API key, require explicit confirmation before sending mail, reading sensitive threads, creating webhooks/SSE listeners, or deleting resources, and treat webhook secrets, attachment URLs, message bodies, and recipient lists as sensitive. Webhook receivers should add replay protection and robust malformed-signature handling.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/webhook-verification.md:7
Finding

Webhook Verification Does Not Prevent Replay Attacks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/webhook-verification.md:57
Finding

Malformed Webhook Signatures Can Trigger an Exception in the Node.js Example

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill encourages reading, sending, replying to, and streaming email through a third-party service but does not prominently warn that message contents, attachments, addresses, and event data may be transmitted to or processed by external infrastructure. Without an explicit privacy/consent warning, an agent may handle sensitive mailbox content or configure real-time forwarding mechanisms like webhooks and SSE without the user understanding the data exposure.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
For full endpoint details including request/response schemas, read `references/api-reference.md`.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 63)May include surrounding context.

}

text

### DELETE /v1/account

Permanently deletes account and all data. Requires `{"confirm": "DELETE"}` in body.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 170)May include surrounding context.

md
The full `key` is shown only in this response. Save it immediately.

### DELETE /v1/api-keys/{id}

Revokes (disables) an API key. Cannot revoke your only active key.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 248)May include surrounding context.

}

text

### DELETE /v1/domains/{id}

Removes a domain. **Response:** `{"deleted": true}`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 317)May include surrounding context.

}

text

### DELETE /v1/mailboxes/{id}

Permanently deletes a mailbox. **Response:** `{"deleted": true}`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 493)May include surrounding context.

md
- `contentId` — for inline images, the `Content-ID` header value (without angle brackets). Match against `cid:foo` references in the HTML body. `null` for normal attachments and outbound uploads.
- `url` — presigned R2 URL valid for 24 hours from the moment of this request. Call this endpoint again for a fresh URL after expiry.

### DELETE /v1/attachments/{id}

Deletes an attachment from storage. **Response:** `{"deleted": true}`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 554)May include surrounding context.

}

text

### DELETE /v1/webhooks/{id}

Deletes a webhook. **Response:** `{"deleted": true}`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 613)May include surrounding context.

}

text

### DELETE /v1/suppressions/{id}

Removes from suppression list. **Response:** `{"deleted": true}`

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list is extremely broad and includes common terms like 'email', 'mail', and 'inbox', which can cause the skill to activate in many ordinary contexts without clear user intent to use an external email service. In an agent setting, over-invocation increases the chance of unintended access to inbox data or unintended outbound actions, especially because this skill can send, read, and stream real email content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents permanent account deletion, and elsewhere also documents deletion of domains, mailboxes, attachments, webhooks, and suppressions, but provides little or no explicit warning language beyond the account endpoint's terse description. Under the markdown-file criteria, destructive behaviors that can affect user data or system integrity should be accompanied by clearer warnings about irreversibility and scope of impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file includes example code that reads WEBHOOK_SECRET from environment variables in both Node.js and Python, but the document does not warn readers that this is sensitive credential material or advise secure handling. Under the markdown-file scope for missing user warnings, examples that involve credentials should disclose the sensitivity to reduce accidental exposure or insecure storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.