Back to skill

Security audit

email-suite (imap+smtp)

Security checks for vulnerabilities and agentic risk

Overview

This email skill is mostly coherent, but it handles a full mailbox with weak safeguards around credentials, permanent deletion, untrusted email content, and attachment downloads.

Review before installing. Use a dedicated app password you can revoke, restrict .env permissions immediately, avoid running this on shared machines, confirm UIDs before deleting, and do not let an agent autonomously follow instructions from email bodies or download attachments from untrusted senders.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/utils/imap.js:674
Finding

Path Traversal Through Untrusted Email Attachment Filenames

Content
View full analysis
``` 4. `mailparser` exposes the attacker-controlled attachment filename. 5. `path.join(dir, att.filename)` constructs a path outside the intended attachment directory. 6. `fs.writeFileSync` creates or overwrites the resulting file with attacker-controlled data. 7. If the overwritten file is later interpreted or executed, the attacker may achieve configuration corruption or code execution in the user's context. ### Impact Assessment The immediate impact is arbitrary file creation or overwrite within the current process user's filesystem permissions. This does not directly grant elevated operating-system privileges, but it can compromise project files, configuration files, scripts, or other ...[truncated 114 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
setup.sh:177
Finding

Email Credentials Are Created Without Enforced Restrictive Permissions

Content
View full analysis
.env << EOF # IMAP Configuration IMAP_HOST=$IMAP_HOST IMAP_PORT=$IMAP_PORT IMAP_USER=$EMAIL IMAP_PASS=$PASSWORD IMAP_TLS=$IMAP_TLS IMAP_REJECT_UNAUTHORIZED=$REJECT_UNAUTHORIZED IMAP_MAILBOX=INBOX # SMTP Configuration SMTP_HOST=$SMTP_HOST SMTP_PORT=$SMTP_PORT SMTP_SECURE=$SMTP_SECURE SMTP_USER=$EMAIL SMTP_PASS=$PASSWORD SMTP_FROM=$EMAIL SMTP_REJECT_UNAUTHORIZED=$REJECT_UNAUTHORIZED # Sender Display Name FROM_NAME="$FROM_NAME" EOF ``` The setup script only recommends changing permissions after creating the file: ```bash echo -e " Run: ${CYAN}chmod 600 .env${NC} to secure your credentials" ``` ### Technical Analysis The setup process stores IMAP and SMTP passwords in plaintext in `.env`. Plaintext storage is expected for this application's authentication mechanism, but the script does not enforce an owner-only creation mode. The resulting permissions depend on the caller's current `umask`. Under a permissive configuration, the file may be readable by other local accounts before the user manually runs the recommended `chmod` command. The user may also overlook that recommendation entirely. The setup script subsequently tests both connections, so valid credentials are already present in the insufficiently protected file at that point. ### Attack Path 1. A user runs `bash setup.sh` under a permissive `umask`. 2. The script prompts for an email password or app password. 3. The script writes that secret to `.env` using ordinary shell redirection. 4. The script does not immediately restrict the file to mode `0600`. 5. Another local user or process with applicable filesystem access reads `.env`. 6. The attacker authenticates to the victim's IMAP or SMTP account using the disclosed credentials. ### Impact Assessment Successfu ...[truncated 404 chars]
Remediation
View remediation
.env chmod 600 .env ``` 3. Prefer writing to a securely created temporary file and atomically renaming it after successful generation. 4. Verify the final mode programmatically and stop setup if owner-only permissions cannot be established. 5. Avoid treating `chmod 600` as an optional post-installation instruction. 6. Retain the recommendation to use limited-purpose app passwords and document how users can revoke them. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utils/imap.js:112
Finding

Sensitive Email Metadata Is Cached With Process-Default Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/utils/imap.js:389
Finding

Untrusted Email Content Is Emitted Directly Into an AI Agent-Facing Response

Content
View full analysis
a.filename).join(', ')}`); } console.log('\n---\n'); console.log(msg.text || msg.html || '(no content)'); console.log('\n---\n'); if (msg.hasAttachments) { console.log('**Has Attachment(s) — download:**'); console.log('```bash'); console.log(`node scripts/mail.js download ${uid}`); console.log('```\n'); } console.log('**Actions:**'); console.log('```bash'); console.log(`node scripts/mail.js reply ${uid} --body "Your reply here"`); console.log(`node scripts/mail.js forward ${uid} --to `); console.log(`node scripts/mail.js mark-unread ${uid}`); console.log(`node scripts/mail.js delete ${uid}`); console.log('```\n'); ``` ### Technical Analysis The project explicitly advertises Markdown output intended for AI agents. Email bodies, subjects, sender fields, and attachment filenames are attacker-controlled content, but they are emitted directly into the same response that contains trusted-looking action hints. An attacker can construct an email that imitates Markdown headings, code blocks, system instructions, or action recommendations. An integrating model may confuse this untrusted content with trusted Skill output and invoke state-changing commands. This is not conventional shell command injection: the application does not execute content directly. Exploitation depends on an AI integration granting the model access to the mail commands without sufficient confirmation or trust-boundary controls. ### Attack Path 1. An attacker sends an email conta ...[truncated 985 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:12
Finding

Dependency Installation Is Not Reproducibly Pinned

Content
View full analysis
/dev/null ``` ### Technical Analysis The project contains no package lock, while all direct dependencies use caret ranges. Consequently, installation can resolve package versions and transitive dependency trees that differ from those reviewed during the audit. The listed package names use ordinary npm package identities; no confirmed typosquatting or dependency-confusion package was identified. The vulnerability is the absence of reproducible integrity controls, not evidence that a listed package is currently malicious. If an allowed future release or transitive dependency is compromised, `npm install` may retrieve and install altered code. Dependency lifecycle scripts, if present in the resolved tree, execute with the privileges of the user running setup. ### Attack Path 1. An upstream package account, permitted release, or transitive dependency is compromised. 2. A changed version remains compatible with one of the declared caret ranges. 3. A user runs `bash setup.sh`. 4. The script executes `npm install` without a committed lockfile. 5. npm resolves and downloads the changed dependency tree. 6. Malicious lifecycle or runtime code executes in the context of the local user. 7. That code may access project data, `.env` credentials, mailbox content available to the process, or other resources accessible by the account. ### Impact Assessment Potential impact is execution of dependency-suppli ...[truncated 297 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (48)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

md
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

md
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

md
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 176)May include surrounding context.

md
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 234)May include surrounding context.

md
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/utils/env.js (reported line 2)May include surrounding context.

js
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/utils/index.js (reported line 5)May include surrounding context.

js
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/utils/smtp.js (reported line 15)May include surrounding context.

js
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 206)May include surrounding context.

sh
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 249)May include surrounding context.

sh
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 250)May include surrounding context.

sh
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 282)May include surrounding context.

sh
/**
 * Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/utils/env.js (reported line 5)May include surrounding context.

js
* Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/utils/smtp.js (reported line 147)May include surrounding context.

js
* Shared .env loading
 */
const path = require('path');
require('dotenv').config({ path: path.resolve(__dirname, '../../.env') });

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The delete command immediately marks messages as \\Deleted and expunges them, permanently removing mail without a confirmation prompt or strong destructive-action warning. In an agent skill that may be invoked through automation or ambiguous user intent, this materially increases the risk of irreversible data loss.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The script is explicitly designed to create a .env file containing email credentials, which introduces a real secret-at-rest risk on disk. In an agent skill context, storing reusable IMAP/SMTP passwords locally is sensitive because other local processes, accidental commits, backups, or misconfigured permissions could expose full mailbox access.

Content

Scanner excerpt · setup.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash

# IMAP/SMTP Email Suite Setup
# Creates .env with email credentials

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This heredoc writes IMAP/SMTP usernames and passwords directly into .env in plaintext. Plaintext credential storage is dangerous because compromise of the working directory, logs, backups, or source control can immediately expose reusable mailbox credentials.

Content

Scanner excerpt · setup.sh (reported line 181)May include surrounding context.

sh
$EMAIL"
    fi

    # Create .env file
    cat > .env << EOF
# IMAP Configuration
IMAP_HOST=$IMAP_HOST

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This is part of the same credential-writing block and stores sensitive configuration, including authentication material, in a local plaintext .env file. In a setup script, this increases the blast radius of any local compromise and makes accidental disclosure more likely.

Content

Scanner excerpt · setup.sh (reported line 182)May include surrounding context.

sh
fi

    # Create .env file
    cat > .env << EOF
# IMAP Configuration
IMAP_HOST=$IMAP_HOST
IMAP_PORT=$IMAP_PORT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README documents node scripts/mail.js delete <uid> as a management command, but it does not include any warning that deleting messages may be destructive or difficult to reverse depending on server behavior. For a markdown skill description, operations affecting user data should be accompanied by a clear warning about their impact on mailbox contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown describes delete <uid> as Delete permanently but does not provide a clear safety warning or caution section about irreversible data loss. Because this skill can remove user email data, the description should explicitly warn users before they invoke destructive operations, especially since multi-delete is also supported.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 216)May include surrounding context.

md
## Security
- Never commit `.env` to git
- `chmod 600 .env` to protect credentials
- Use App Passwords for Gmail/Outlook (2FA required)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
## Security
- Never commit `.env` to git
- `chmod 600 .env` to protect credentials
- Use App Passwords for Gmail/Outlook (2FA required)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 284)May include surrounding context.

sh
## Security
- Never commit `.env` to git
- `chmod 600 .env` to protect credentials
- Use App Passwords for Gmail/Outlook (2FA required)

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/utils/imap.js:17