Back to skill

Security audit

Lumail

Security checks for vulnerabilities and agentic risk

Overview

This Lumail skill is purpose-aligned but needs review because it guides agents toward live email, subscriber, campaign, token, and npm package actions without enough scoping or safety controls.

Review this before installing if you expect agents to act on real Lumail data. Use least-privilege API tokens, avoid raw token display, require explicit user confirmation before sends, deletes, unsubscribes, or campaign changes, and pin or otherwise verify the Lumail npm package before running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:357
Finding

Unpinned Third-Party npm Package Installation and Execution

Content
View full analysis
npx lumail subscribers create --email user@example.com ``` ### Technical Analysis The skill directs users to globally install and execute the third-party `lumail` npm package without specifying an exact version, lockfile, or package integrity hash. The audited project contains only `SKILL.md`; it does not contain the referenced CLI or SDK source, dependency manifest, release workflow, or tests. Consequently, the code installed from npm cannot be verified against the reviewed artifact. An unpinned installation may retrieve a newer package release than the one intended when the skill was authored. npm package installation may also execute package lifecycle scripts, while subsequent `npx lumail` commands execute code supplied by the package. This creates a supply-chain trust boundary through which a compromised maintainer account, malicious package release, package replacement, or other registry compromise could introduce arbitrary code after this skill has been reviewed. The authentication command supplies a Lumail API token to the installed program. A malicious package could capture that token in addition to exercising the local permissions of the user running the command. ### Attack Path 1. An attacker compromises the referenced npm package, its publisher account, or its release process and publishes a malicious version. 2. A user follows the skill's instruction to run `npm install -g lumail` without an exact version or verified integrity digest. 3. npm retrieves the malicious release and may execute its lifecycle scripts with the privileges of the current user. 4. The user invokes `npx lumail auth set `, causing package-controlled code to receive the Lumail API token. ...[truncated 951 chars]
Remediation
View remediation
``` 2. Publish and verify the expected npm integrity digest or package provenance before installation. Use registry signatures and npm provenance attestations where available. 3. Provide a dependency manifest and lockfile that resolve the exact reviewed package version and transitive dependencies. 4. Link the package to a verifiable official source repository and release commit. Ensure the distributed npm artifact can be reproducibly matched to that source. 5. Include the CLI and SDK implementation in the audited skill artifact, or make the reviewed release artifact available for independent inspection. 6. Avoid global installation where possible. Run the tool in a restricted project environment, container, or dedicated low-privilege account. 7. Disable npm lifecycle scripts during installation where compatible: ```bash npm install --ignore-scripts lumail@ ``` 8. Issue a least-privilege Lumail API token with only the permissions required for the requested operation. Do not expose administrative credentials to the CLI. 9. Store the token using an operating-system credential manager or similarly protected secret store rather than relying solely on a plaintext configuration path. 10. Add an explicit confirmation step before destructive or externally visible operations such as deleting subscribers, sending campaigns, or sending transactional email. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger language is broad enough to activate this skill for generic email-related requests, not just Lumail-specific tasks. That can route an agent into using powerful email marketing and sending capabilities in situations where the user did not explicitly request Lumail, increasing the chance of unintended external actions, privacy issues, or misuse of stored credentials. In this context, broad auto-selection is especially risky because the skill includes send, delete, unsubscribe, and event-creation operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation presents destructive and externally impactful commands such as delete, unsubscribe, send, and authentication token handling without clear warnings or confirmation requirements. This can normalize dangerous copy-paste actions, lead agents or users to expose credentials via auth show --raw, and cause irreversible changes or outbound email actions without adequate notice. The risk is elevated because the skill is specifically designed to operate on real subscriber data and live email infrastructure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The documentation instructs users to run npx lumail without pinning a specific package version. That causes execution of whatever version npm resolves at runtime, which can unexpectedly introduce malicious or compromised code if the package, dependency chain, or release channel is tampered with. In a skill meant to guide automated agents, this is more dangerous because the instruction may be followed non-interactively and repeatedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx lumail without a version pin on this line has the same supply-chain risk: it executes the latest package selected by npm at runtime. If an attacker compromises the package or publishes a harmful update, users or agents following the skill can run unreviewed code immediately. Because this skill also handles API credentials, compromise could lead to token theft or unauthorized email operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.