Back to skill

Security audit

Delivery Notifier

Security checks for vulnerabilities and agentic risk

Overview

The skill broadly matches its delivery-notification purpose, but it handles private Gmail data too broadly and sends delivery details to a fixed WhatsApp number.

Install only if you intend this skill to read the configured Gmail inbox and send delivery metadata to the listed WhatsApp number. Before use, change the recipient to your own controlled destination, remove or restrict the debug script, store only minimal deduplication data, and protect or relocate the state file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/delivery_notifier_debug.py:28
Finding

Debug Utility Exposes Complete Private Email Contents in Logs

Content
View full analysis
1: print(f"Response part[1] type: {type(response_part[1])}") if response_part[1] is not None: msg = email.message_from_bytes(response_part[1]) subject_parts = decode_header(msg["Subject"]) subject = "".join([part.decode(encoding if encoding else 'utf-8', errors='replace') if isinstance(part, bytes) else str(part) for part, encoding in subject_parts]) from_ = str(msg.get("From")) body = msg.get_payload(decode=True).decode(errors='replace') results.append({"id": e_id.decode() if isinstance(e_id, bytes) else str(e_id), "from": from_, "subject": subject, "body": body}) ``` ```python notifications = fetch_delivery_notifications() print(json.dumps(notifications, indent=2)) ``` ### Technical Analysis The debug utility retrieves messages with the IMAP `RFC822` fetch attribute, which returns the complete email record. This can include message headers, sender and recipient addresses, message bodies, MIME structure, and attachment data. The script writes the raw IMAP response directly to standard output. It then parses the message, stores its full body in `results`, and serializes that result to standard output again. Consequently, sensitive mailbox information is disclosed twice. If the utility is executed under cron, CI, a service manager, a remote shell, or an environment with terminal recording or centralized log collection, complete email records may be retained out ...[truncated 1392 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/delivery_notifier.py:224
Finding

Complete Email Bodies Are Persisted in Plaintext State

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/delivery_notifier.py:264
Finding

Delivery Metadata Is Forwarded to a Hard-Coded Personal WhatsApp Recipient

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code prints raw IMAP fetch responses and message parts, which can include full email headers, bodies, and other sensitive mailbox contents. Debug output is often captured in logs, terminals, CI systems, or monitoring tools, turning transient mailbox access into broader unintended data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description states it scans a Gmail inbox, extracts delivery details, and forwards formatted alerts to WhatsApp, but it does not prominently warn users that email content and potentially sensitive shipment data will be accessed and transmitted to a third-party messaging platform. This creates a real privacy and consent risk because users may enable or schedule the skill without fully understanding the scope of data collection, processing, and disclosure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file-level documentation says the notifier filters out marketing spam, but MARKETING_SENDERS is empty, so the only real filter is whether a message mentions courier names or delivery keywords. That means the documented anti-spam behavior is not actually implemented as described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script forwards email-derived data, including subject lines and tracking numbers, to an external WhatsApp destination without any consent gate, minimization, or clear disclosure. If sensitive order or delivery details appear in those fields, private mailbox contents are unnecessarily exposed to a third-party messaging channel and any party with access to that WhatsApp account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The WhatsApp message template uses Romanian-only labels such as "LIVRARE NOUĂ", "Curier", "Trimitere", and "Mesaj" with no configuration or user choice. This imposes a specific locale on all users and matches the policy concern around forced language without opt-in.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
55% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/delivery_notifier.py (reported line 305)May include surrounding context.

python
"""Main function"""
    print(f"Fetching delivery notifications at {datetime.now()}...")

    # Load previous state
    state = load_state()
    print(f"Loaded state with {len(state.get('notifications', []))} previous notifications")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script reads Gmail credentials from environment variables and uses them to authenticate to a live mailbox without any visible access control, consent flow, or strong justification in the file itself. Credentialed mailbox access is highly sensitive because it enables reading private communications and can expose account data if the skill is run in an unexpected context or with overprivileged credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script silently consumes mailbox credentials from environment variables and logs into Gmail without visible disclosure or operator confirmation. In a skill or automation context, hidden credential use is risky because users may not realize the code will access a personal mailbox when those environment variables are present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Fetching sensitive email messages and printing debug output exposes private content without any warning, disclosure, or indication to the operator that mailbox data will be emitted. This increases the risk of accidental privacy violations and secondary leakage through logs or shared consoles.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented output format uses Romanian phrases such as "LIVRARE NOUĂ" and "Comanda dumneavoastră a fost expediată", which indicates a fixed language choice. The file does not mention that the skill is region-specific or provide the user with a language or locale option, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The inline comments indicate a more specific search for delivery notifications, yet the actual IMAP query is a single broad criterion: SUBJECT "Delivery". This is a direct contradiction between the comment's stated intent and the implemented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.