Back to skill

Security audit

Email Daily Summary Zc

Security checks for vulnerabilities and agentic risk

Overview

This skill has a clear email-summary purpose, but it asks for broad authenticated mailbox access and unattended scheduled runs with weak credential and dependency safeguards.

Review carefully before installing. Use only a dedicated browser profile or read-only mailbox account, avoid entering real passwords in shell commands, do not enable the cron or launchd schedule unless you understand how to disable it, and treat generated screenshots, logs, and AI summaries as sensitive email data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Unpinned Third-Party Dependency Installed with Access to Authenticated Browser Sessions

Content
View full analysis
Remediation
View remediation
" ``` 2. Maintain a lockfile containing exact transitive dependency versions. 3. Require package hashes where the package-management workflow supports them. 4. Explicitly identify and enforce the trusted package registry or index. 5. Document the versions and integrity controls applied by `browser-use install`. 6. Install and run the dependency in an isolated environment with only the permissions needed for mailbox summarization. 7. Avoid exposing an entire everyday browser profile where a dedicated, minimally privileged browser profile or provider API with read-only scopes can perform the task. 8. Review dependency updates before changing the pinned version and automate vulnerability scanning of the resolved dependency tree. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:52
Finding

Email Password Exposed Through a Command-Line Argument

Content
View full analysis
"your-email@gmail.com" browser-use click # Enter the password browser-use input "your-password" browser-use click # Navigate to the mailbox browser-use open https://mail.google.com ``` ### Technical Analysis The example encourages replacing `"your-password"` with an actual mailbox password supplied as a command-line argument. Secrets passed this way can be retained in shell history and terminal transcripts. Depending on the operating system and process behavior, command arguments may also be observable through process-inspection interfaces, endpoint-monitoring products, audit logs, or diagnostic collection. The later recommendation not to save plaintext passwords in scripts does not eliminate exposure caused by entering the password directly in a shell command. Environment variables alone are also not an ideal remedy because they can leak through process environments, debugging output, or child processes. ### Attack Path 1. A user follows the manual-login example and substitutes a real email password for `"your-password"`. 2. The shell records the command in its history, or another local monitoring or logging mechanism captures the command line. 3. A local user, support operator, malware process, backup reader, or monitoring-system user obtains access to that record. 4. The attacker extracts the plaintext mailbox password. 5. The attacker authenticates to the mailbox directly, subject to any multifactor authentication or provider controls. 6. If the password has be ...[truncated 893 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill's core behavior is to access logged-in email accounts and collect private mailbox content, including message metadata and screenshots. Even if intended for legitimate summaries, this processes highly sensitive personal and business data and creates significant confidentiality risk if run without strict minimization, consent, and output protections.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These instructions automate extraction of sender, subject, snippet, and timestamp from multiple emails using DOM scraping. In context, this is dangerous because it operationalizes bulk collection of private communications from authenticated sessions, increasing the chance of unauthorized disclosure, overcollection, or downstream misuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The AI extraction step sends or prepares the first 10 emails' sender, subject, and summaries for automated processing, which can expose sensitive communications to an external model or service. The danger is elevated because the workflow encourages broad inbox summarization rather than targeted, minimally necessary access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill uses Chinese for its core user-facing instructions, which effectively imposes a specific language on users. The file does not provide an alternative language option or indicate that the locale is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs installation of additional software and browser automation tooling, expanding the host attack surface beyond simple summarization. While the install step is plausibly functional rather than malicious, it is not tightly scoped and enables broader automated access to a user's browsing context and email sessions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents cron and launchd persistence so mailbox access and data collection can recur automatically without fresh user initiation. Persistent scheduled execution is an OS-level capability that materially increases privacy and abuse risk for a skill whose purpose is summarizing email.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Editing crontab to run the email summary automatically establishes persistence for repeated mailbox access and data generation. In this context, persistence increases the chance of unnoticed collection of sensitive email data and normalizes ongoing access to authenticated sessions.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

bash
# 编辑 crontab
crontab -e

# 添加每日早上 9 点执行的任务
0 9 * * * /path/to/email_daily_summary.sh >> /path/to/logs/email_summary.log 2>&1

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The launchd plist creation instructions establish a persistent background task on macOS for repeated execution. For a skill handling email contents, this persistence materially raises privacy and misuse risks because it enables unattended recurring access and output generation.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

macOS (launchd)

创建 ~/Library/LaunchAgents/com.email.dailysummary.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This duplicate finding points to the same launchd plist persistence mechanism. Although not inherently malicious, embedding OS persistence guidance in a data-sensitive email skill broadens abuse potential and reduces user awareness of ongoing collection.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This duplicate finding points to the same launchd plist persistence mechanism. Although not inherently malicious, embedding OS persistence guidance in a data-sensitive email skill broadens abuse potential and reduces user awareness of ongoing collection.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The LaunchAgent label and associated plist content are operational pieces of persistence, allowing recurring execution after setup. Because the skill accesses authenticated email sessions, persistence increases confidentiality risk and makes accidental long-term collection more likely.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>
    <string>com.email.dailysummary</string>

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The persistence configuration also specifies log files, which can accumulate sensitive operational details and potentially mailbox-derived content over time. Combined with scheduled execution, this increases both persistence and local data exposure risk.

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

StandardErrorPath /tmp/email_summary_error.log

text

加载任务:

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This duplicate finding refers to the same launchctl load activation of the plist-based persistent task. The security issue is the same: unattended repeated access to sensitive email content via an OS persistence mechanism.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

加载任务:

bash
launchctl load ~/Library/LaunchAgents/com.email.dailysummary.plist

输出示例

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This duplicate finding refers to the same launchctl load activation of the plist-based persistent task. The security issue is the same: unattended repeated access to sensitive email content via an OS persistence mechanism.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

加载任务:

bash
launchctl load ~/Library/LaunchAgents/com.email.dailysummary.plist

输出示例

Static analysis

No suspicious patterns detected.