Back to skill

Security audit

MailMolt - Email for AI Agents

Security checks for vulnerabilities and agentic risk

Overview

MailMolt is a coherent email-agent skill, but it has review-worthy risks around outbound email approval, broad natural-language triggers, and API key handling.

Install only if you are comfortable giving the agent a MailMolt mailbox and the ability, at higher permission levels, to send email through MailMolt. Use a secret store or tightly permissioned environment variable for the API key, keep the account in sandbox or supervised mode where possible, review all outgoing messages manually, avoid broad auto-reply workflows, and be cautious with webhooks or linking other service API keys.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:45
Finding

MailMolt API Key Stored in a Plaintext Credential File Without Required Access Controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
handlers.ts:229
Finding

Direct Email Handlers Bypass the Locally Declared Human-Approval Requirement

Content
View full analysis
{ const { config, log } = context; if (!params.to || !params.subject || !params.body) { return 'Please provide recipient (to), subject, and body for the email.'; } log(`Sending email to ${params.to}...`); const response = await apiRequest(config, 'POST', '/v1/messages', { to: [params.to], subject: params.subject, text: params.body, }) as { message: { id: string; status: string } }; return `Email sent successfully to ${params.to}.\nSubject: ${params.subject}\nStatus: ${response.message.status}`; } /** * Reply to an email */ ex ...[truncated 3639 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (27)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs storing a live API key in a plaintext file under a predictable path, which materially increases the risk of credential theft by other local processes, users, backups, or logs. If the token is compromised, an attacker could access mailbox data, send messages, and manage integrations on behalf of the agent.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

2. Save credentials

Store in ~/.config/mailmolt/credentials.json:

json
{
  "api_key": "mm_live_xxxxx",

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The send_email handler transmits outbound email content directly to an external service as soon as parameters are provided, with no confirmation, preview, or policy check. In an agent setting, prompt injection, misunderstanding, or ambiguous instructions could cause unintended external disclosure to arbitrary recipients.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The reply_email handler sends a reply immediately using either a supplied message_id or a remembered last_message_id from prior context, without confirming the target message or reply contents. This increases the risk of accidental replies to the wrong thread and unintended disclosure of sensitive information to external parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

1. Register for an email address

bash
curl -X POST https://api.mailmolt.com/v1/agents/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "your-agent-name",

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Generic inbox-check phrases can cause the skill to activate during unrelated conversation and retrieve email content without sufficiently explicit user intent. Because inbox access may expose sensitive message metadata or contents, accidental invocation can leak private information into the agent context or UI.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes send/reply features without a prominent warning that message content, recipients, and related metadata will be transmitted to a third-party service and external email recipients. Users may unknowingly provide sensitive data to the skill under the assumption it is local or low-risk, increasing privacy and compliance exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrase for sending email is broad and action-oriented, allowing ordinary conversational requests to be interpreted as authorization to transmit content externally. In a skill that can send to arbitrary recipients at higher trust levels, ambiguous invocation raises the risk of unintended data disclosure or unauthorized outbound communication.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

This documented action sends email content to an external service and then to a recipient, which can expose sensitive reports or user data if invoked without strong consent and review. In context, the skill explicitly encourages direct emailing of a human owner, making outbound transmission a core capability that needs clear safeguards.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

When heartbeat shows human_owner.email_verified: true, you can email them directly:

bash
curl -X POST https://api.mailmolt.com/v1/messages \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"to": ["owner@gmail.com"], "subject": "Daily Report", "text": "..."}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

This documented action sends email content to an external service and then to a recipient, which can expose sensitive reports or user data if invoked without strong consent and review. In context, the skill explicitly encourages direct emailing of a human owner, making outbound transmission a core capability that needs clear safeguards.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

When heartbeat shows human_owner.email_verified: true, you can email them directly:

bash
curl -X POST https://api.mailmolt.com/v1/messages \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"to": ["owner@gmail.com"], "subject": "Daily Report", "text": "..."}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The webhook creation feature enables forwarding event data to an arbitrary URL, which can exfiltrate message metadata or contents to external infrastructure if misconfigured or abused. In an agent skill context, allowing broad webhook destinations without constraints expands the outbound data surface significantly.

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

Get notified instantly when email arrives:

bash
curl -X POST https://api.mailmolt.com/v1/webhooks \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"url": "https://your-server/webhook", "event_types": ["message.received"]}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

The referral feature causes the agent to send messages to third-party email addresses, creating a risk of unsolicited contact, privacy leakage, or misuse of user-provided contacts. Because this is outbound communication to arbitrary recipients, accidental or automated use can have spam and data-sharing consequences.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

Refer other agents

bash
curl -X POST https://api.mailmolt.com/v1/agents/refer \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"to_email": "friend@somewhere.com", "message": "Get your own email!"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Linking a separate Moltbook API key to this service introduces credential sharing across systems, expanding the blast radius if MailMolt or the integration is compromised. The skill encourages posting and cross-service linking without discussing token scope, storage, or revocation, which increases account takeover and cross-platform abuse risk.

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

If you have a Moltbook account, link it to auto-announce:

bash
curl -X POST https://api.mailmolt.com/v1/agents/link-moltbook \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"moltbook_api_key": "moltbook_xxx"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 291)May include surrounding context.

md
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · config.json (reported line 21)May include surrounding context.

json
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · mailmolt-hook.json (reported line 171)May include surrounding context.

json
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · mailmolt-hook.json (reported line 192)May include surrounding context.

json
"moltbot": {
    "emoji": "📧",
    "category": "communication",
    "api_base": "https://api.mailmolt.com/v1",
    "skill_files": {
      "main": "https://mailmolt.com/skill.md",
      "heartbeat": "https://mailmolt.com/heartbeat.md"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The handler trigger set includes broad everyday phrases such as 'messages' and 'any mail' that can plausibly appear in normal conversation and unintentionally activate email-related actions. In a communication skill with external network capabilities, accidental invocation can expose inbox contents or initiate actions the user did not explicitly request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The pattern 'what did .* say' is effectively unbounded natural language matching and is highly ambiguous, making unintended activation likely during ordinary dialogue. Because this handler reads message threads, accidental matches could disclose email content without a clear, intentional command from the user.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Triggers like 'write to', 'message to', and 'reply to' are common conversational phrases and are not sufficiently scoped to email operations. In a skill that can send external communications, such ambiguity can lead to unintended outbound emails, disclosure of sensitive information, or unauthorized replies.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Phrases such as 'check status', 'what should I do', and 'action items' are generic prompts that may occur in routine conversation and unintentionally invoke the heartbeat workflow. Since heartbeat appears to fetch remote status and possibly recommended actions, accidental activation can trigger unnecessary network requests and influence agent behavior unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.