Back to skill

Security audit

Mermail Support Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Mermail support-inbox assistant with disclosed email access and clear human approval requirements for sends, forwards, and deletion.

Install only for a Mermail workspace where the agent should read and manage support mail. Review outgoing recipients and message bodies before approval, and treat mailbox creation, triager updates, forwarding, and deletion as durable actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.