T09 · Insecure Skill Coding Practices
- Location
references/webhook-verification.md:7- Finding
Webhook Verification Does Not Prevent Replay Attacks
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Robotomail is a coherent email-integration skill, but it gives an agent broad real-mailbox authority without enough user-control and privacy warnings.
Install only if you intend to let an agent use Robotomail for real email. Prefer a mailbox-scoped API key, require explicit confirmation before sending mail, reading sensitive threads, creating webhooks/SSE listeners, or deleting resources, and treat webhook secrets, attachment URLs, message bodies, and recipient lists as sensitive. Webhook receivers should add replay protection and robust malformed-signature handling.
references/webhook-verification.md:7Webhook Verification Does Not Prevent Replay Attacks
references/webhook-verification.md:57Malformed Webhook Signatures Can Trigger an Exception in the Node.js Example
The skill encourages reading, sending, replying to, and streaming email through a third-party service but does not prominently warn that message contents, attachments, addresses, and event data may be transmitted to or processed by external infrastructure. Without an explicit privacy/consent warning, an agent may handle sensitive mailbox content or configure real-time forwarding mechanisms like webhooks and SSE without the user understanding the data exposure.
Referenced artifact was not completely inspected
For full endpoint details including request/response schemas, read `references/api-reference.md`.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
}
### DELETE /v1/account
Permanently deletes account and all data. Requires `{"confirm": "DELETE"}` in body.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
The full `key` is shown only in this response. Save it immediately.
### DELETE /v1/api-keys/{id}
Revokes (disables) an API key. Cannot revoke your only active key.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
}
### DELETE /v1/domains/{id}
Removes a domain. **Response:** `{"deleted": true}`
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
}
### DELETE /v1/mailboxes/{id}
Permanently deletes a mailbox. **Response:** `{"deleted": true}`
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- `contentId` — for inline images, the `Content-ID` header value (without angle brackets). Match against `cid:foo` references in the HTML body. `null` for normal attachments and outbound uploads.
- `url` — presigned R2 URL valid for 24 hours from the moment of this request. Call this endpoint again for a fresh URL after expiry.
### DELETE /v1/attachments/{id}
Deletes an attachment from storage. **Response:** `{"deleted": true}`
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
}
### DELETE /v1/webhooks/{id}
Deletes a webhook. **Response:** `{"deleted": true}`
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
}
### DELETE /v1/suppressions/{id}
Removes from suppression list. **Response:** `{"deleted": true}`
The trigger list is extremely broad and includes common terms like 'email', 'mail', and 'inbox', which can cause the skill to activate in many ordinary contexts without clear user intent to use an external email service. In an agent setting, over-invocation increases the chance of unintended access to inbox data or unintended outbound actions, especially because this skill can send, read, and stream real email content.
This markdown file documents permanent account deletion, and elsewhere also documents deletion of domains, mailboxes, attachments, webhooks, and suppressions, but provides little or no explicit warning language beyond the account endpoint's terse description. Under the markdown-file criteria, destructive behaviors that can affect user data or system integrity should be accompanied by clearer warnings about irreversibility and scope of impact.
This markdown file includes example code that reads WEBHOOK_SECRET from environment variables in both Node.js and Python, but the document does not warn readers that this is sensitive credential material or advise secure handling. Under the markdown-file scope for missing user warnings, examples that involve credentials should disclose the sensitivity to reduce accidental exposure or insecure storage.
No suspicious patterns detected.