Back to skill

Security audit

Mailbird

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed Mailbird email integration that uses a local MCP server and mailbox token, with no bundled code or hidden persistence found.

Install only if you intend to let the agent access Mailbird email on this machine. Keep MAILBIRD_MCP_URL on 127.0.0.1 or localhost, keep the token private, enable Mailbird's audit log if you want visibility, and review any draft before allowing sends.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:4
Finding

Unenforced Loopback Restriction May Expose the Mailbox Bearer Token

Content
View full analysis
Remediation
View remediation
/mcp` - `http://localhost:/mcp` 3. Reject: - Non-HTTP schemes. - Non-loopback IP addresses. - Hostnames that resolve to any non-loopback address. - URLs containing user-information components. - Unexpected paths, query strings, or fragments. - Ambiguous or alternative IP representations that could bypass string-based checks. 4. Disable redirects, or revalidate every redirect destination and strip the `Authorization` header before following it. Credentials must never be forwarded to a different origin. 5. Prefer removing endpoint configurability if custom ports are the only required variation. Store the port separately and construct the loopback URL internally. 6. Fail closed when URL parsing, DNS resolution, or loopback validation is inconclusive. 7. Add automated negative tests covering external hosts, IPv6 addresses, encoded hostnames, redirects, DNS rebinding scenarios, and malformed URLs. 8. Rotate `MAILBIRD_MCP_TOKEN` immediately if it may have been transmitted to an untrusted endpoint. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.