T09 · Insecure Skill Coding Practices
- Location
SKILL.md:45- Finding
MailMolt API Key Stored in a Plaintext Credential File Without Required Access Controls
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
MailMolt is a coherent email-agent skill, but it has review-worthy risks around outbound email approval, broad natural-language triggers, and API key handling.
Install only if you are comfortable giving the agent a MailMolt mailbox and the ability, at higher permission levels, to send email through MailMolt. Use a secret store or tightly permissioned environment variable for the API key, keep the account in sandbox or supervised mode where possible, review all outgoing messages manually, avoid broad auto-reply workflows, and be cautious with webhooks or linking other service API keys.
SKILL.md:45MailMolt API Key Stored in a Plaintext Credential File Without Required Access Controls
handlers.ts:229Direct Email Handlers Bypass the Locally Declared Human-Approval Requirement
The skill instructs storing a live API key in a plaintext file under a predictable path, which materially increases the risk of credential theft by other local processes, users, backups, or logs. If the token is compromised, an attacker could access mailbox data, send messages, and manage integrations on behalf of the agent.
Store in ~/.config/mailmolt/credentials.json:
{
"api_key": "mm_live_xxxxx",
The send_email handler transmits outbound email content directly to an external service as soon as parameters are provided, with no confirmation, preview, or policy check. In an agent setting, prompt injection, misunderstanding, or ambiguous instructions could cause unintended external disclosure to arbitrary recipients.
The reply_email handler sends a reply immediately using either a supplied message_id or a remembered last_message_id from prior context, without confirming the target message or reply contents. This increases the risk of accidental replies to the wrong thread and unintended disclosure of sensitive information to external parties.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://api.mailmolt.com/v1/agents/register \
-H "Content-Type: application/json" \
-d '{
"name": "your-agent-name",
Generic inbox-check phrases can cause the skill to activate during unrelated conversation and retrieve email content without sufficiently explicit user intent. Because inbox access may expose sensitive message metadata or contents, accidental invocation can leak private information into the agent context or UI.
The skill describes send/reply features without a prominent warning that message content, recipients, and related metadata will be transmitted to a third-party service and external email recipients. Users may unknowingly provide sensitive data to the skill under the assumption it is local or low-risk, increasing privacy and compliance exposure.
The trigger phrase for sending email is broad and action-oriented, allowing ordinary conversational requests to be interpreted as authorization to transmit content externally. In a skill that can send to arbitrary recipients at higher trust levels, ambiguous invocation raises the risk of unintended data disclosure or unauthorized outbound communication.
This documented action sends email content to an external service and then to a recipient, which can expose sensitive reports or user data if invoked without strong consent and review. In context, the skill explicitly encourages direct emailing of a human owner, making outbound transmission a core capability that needs clear safeguards.
When heartbeat shows human_owner.email_verified: true, you can email them directly:
curl -X POST https://api.mailmolt.com/v1/messages \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"to": ["owner@gmail.com"], "subject": "Daily Report", "text": "..."}'
This documented action sends email content to an external service and then to a recipient, which can expose sensitive reports or user data if invoked without strong consent and review. In context, the skill explicitly encourages direct emailing of a human owner, making outbound transmission a core capability that needs clear safeguards.
When heartbeat shows human_owner.email_verified: true, you can email them directly:
curl -X POST https://api.mailmolt.com/v1/messages \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"to": ["owner@gmail.com"], "subject": "Daily Report", "text": "..."}'
The webhook creation feature enables forwarding event data to an arbitrary URL, which can exfiltrate message metadata or contents to external infrastructure if misconfigured or abused. In an agent skill context, allowing broad webhook destinations without constraints expands the outbound data surface significantly.
Get notified instantly when email arrives:
curl -X POST https://api.mailmolt.com/v1/webhooks \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"url": "https://your-server/webhook", "event_types": ["message.received"]}'
The referral feature causes the agent to send messages to third-party email addresses, creating a risk of unsolicited contact, privacy leakage, or misuse of user-provided contacts. Because this is outbound communication to arbitrary recipients, accidental or automated use can have spam and data-sharing consequences.
curl -X POST https://api.mailmolt.com/v1/agents/refer \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"to_email": "friend@somewhere.com", "message": "Get your own email!"}'
Linking a separate Moltbook API key to this service introduces credential sharing across systems, expanding the blast radius if MailMolt or the integration is compromised. The skill encourages posting and cross-service linking without discussing token scope, storage, or revocation, which increases account takeover and cross-platform abuse risk.
If you have a Moltbook account, link it to auto-announce:
curl -X POST https://api.mailmolt.com/v1/agents/link-moltbook \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"moltbook_api_key": "moltbook_xxx"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"moltbot": {
"emoji": "📧",
"category": "communication",
"api_base": "https://api.mailmolt.com/v1",
"skill_files": {
"main": "https://mailmolt.com/skill.md",
"heartbeat": "https://mailmolt.com/heartbeat.md"
The handler trigger set includes broad everyday phrases such as 'messages' and 'any mail' that can plausibly appear in normal conversation and unintentionally activate email-related actions. In a communication skill with external network capabilities, accidental invocation can expose inbox contents or initiate actions the user did not explicitly request.
The pattern 'what did .* say' is effectively unbounded natural language matching and is highly ambiguous, making unintended activation likely during ordinary dialogue. Because this handler reads message threads, accidental matches could disclose email content without a clear, intentional command from the user.
Triggers like 'write to', 'message to', and 'reply to' are common conversational phrases and are not sufficiently scoped to email operations. In a skill that can send external communications, such ambiguity can lead to unintended outbound emails, disclosure of sensitive information, or unauthorized replies.
Phrases such as 'check status', 'what should I do', and 'action items' are generic prompts that may occur in routine conversation and unintentionally invoke the heartbeat workflow. Since heartbeat appears to fetch remote status and possibly recommended actions, accidental activation can trigger unnecessary network requests and influence agent behavior unexpectedly.
No suspicious patterns detected.