Back to skill

Security audit

Email Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the advertised local email inbox analysis and does not show hidden execution, persistence, exfiltration, or destructive behavior.

Install only if you are comfortable letting the skill read metadata from your configured email account and display sender names and subject lines in reports. Run it intentionally for mailbox analysis, avoid routing casual email questions to it automatically, and consider JSON/text outputs sensitive because they can reveal contacts and communication patterns.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs use of shell commands and external CLI access to a live mailbox, but it does not declare any explicit tool scope or permissions. That mismatch can cause the agent to invoke shell capabilities without clear sandboxing or user-visible authorization boundaries, increasing the chance of unintended mailbox access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level description uses broad everyday phrasing like inbox status, overwhelm, and who they're ghosting, which can cause the skill to activate in casual conversations where the user did not intend mailbox inspection. In this context, unintended activation is dangerous because the skill accesses sensitive email content via IMAP.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'When to Use' section lists ambiguous triggers such as email overwhelm, signal vs noise, and inbox health without requiring an explicit request to connect to and analyze a mailbox. Because this skill works against real IMAP data, ambiguous routing increases the risk of privacy-invasive execution from loosely related user prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Although the requirements mention himalaya CLI configured with IMAP, the skill does not clearly warn users that it will access and analyze mailbox contents. This is a significant transparency and privacy issue because users may not realize the skill reads potentially sensitive emails, sender data, and message history.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/email_classify.py (reported line 26)May include surrounding context.

python
"--page-size", str(int(page_size)),
            "-o", "json"
        ]
        result = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/email_classify.py (reported line 234)May include surrounding context.

python
"""Auto-discover email folders. Returns dict with 'inbox' and 'archive' keys."""
    folders = {'inbox': 'INBOX', 'archive': None, 'sent': None, 'junk': None}
    try:
        result = subprocess.run(
            ["himalaya", "folder", "list", "-o", "json"],
            capture_output=True, text=True, timeout=10, stderr=subprocess.DEVNULL
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill reads mailbox metadata and emits privacy-sensitive details such as sender names, sender email addresses, subject lines, unread status, and inferred relationship/response patterns without any built-in consent prompt, warning, or minimization. In the context of an inbox-analysis skill, this is especially sensitive because the output can reveal personal contacts, work relationships, and communication habits to the caller or to downstream logs/UI surfaces.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.