Back to skill

Security audit

Neynar Inbox

Security checks for vulnerabilities and agentic risk

Overview

The skill is an email API helper, but it recommends recurring inbox polling without limits or cleanup, which could keep using an email API key in the background.

Install only if you are comfortable using Neynar's hosted email API for agent mail. Avoid letting an agent create cron, heartbeat, or other recurring polling unless you explicitly approve the schedule, set an end time, store the API key securely, and know how to remove the task or rotate the key.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Warning
Location
SKILL.md:60
Finding

Unbounded Persistent Email Polling via Scheduled Tasks

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 60
Vulnerability Type: Persistent scheduled network activity
Risk Level: Medium

Vulnerable Code Snippet:

markdown
**RECOMMENDED: If you have heartbeat, cron, or scheduling capabilities, set up polling (every 30-60 seconds) right after creating your mailbox to catch replies.**

Technical Analysis

The skill recommends creating a recurring heartbeat, cron job, or equivalent scheduled task immediately after mailbox creation. The instruction does not define an expiration time, maximum number of requests, task-scoped lifetime, cleanup procedure, or requirement to obtain explicit user approval.

If followed by an agent with scheduling capabilities, the resulting task can continue operating across sessions and after the original skill invocation has ended. Each poll sends the mailbox bearer API key to the external email API. Although the network destination is consistent with the skill's stated email functionality, indefinite background polling unnecessarily extends credential use and external communication beyond the initiating task.

The instruction is conditional and does not itself install a scheduled task. Exploitation therefore requires an agent that can create persistent schedules and that follows the recommendation without requesting approval.

Attack Path

  1. The agent loads the skill and creates a hosted mailbox.
  2. The external service returns a bearer API key for mailbox access.
  3. Following the recommendation at line 60, the agent creates a heartbeat, cron job, or other recurring task.
  4. The scheduled task polls the external inbox endpoint every 30–60 seconds while attaching the bearer API key.
  5. Because no termination or cleanup condition is specified, the task may survive the original run and continue making authenticated requests indefinitely.
  6. Continued execution increases credential exposure, consumes local and remote resou ...[truncated 702 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not create heartbeat, cron, or other persistent tasks without explicit, informed user approval.
  • Prefer on-demand inbox checks or the documented webhook mechanism instead of frequent polling.
  • If polling is necessary, impose a finite duration, maximum request count, exponential backoff, and a clearly defined termination condition.
  • Scope any schedule to the current task or session where technically possible.
  • Record the identifier and configuration of every created scheduled task so it can be reliably removed.
  • Automatically delete the schedule when the task completes, the mailbox is deleted, authentication fails, or the configured lifetime expires.
  • Inform the user that recurring requests transmit the bearer API key to the external service.
  • Store the API key in an approved secret store rather than embedding it directly in cron commands, logs, process arguments, or scheduler configuration.
  • Rotate or revoke the API key after polling is disabled or if unintended persistence is detected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

1. Create a mailbox (no auth needed)

bash
curl -X POST https://neynar-inbox-api.rish-68c.workers.dev/v1/mailboxes \
  -H "Content-Type: application/json" \
  -d '{"displayName": "My Agent", "username": "myagent"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

Register a webhook for real-time email notifications:

bash
curl -X POST https://neynar-inbox-api.rish-68c.workers.dev/v1/webhooks \
  -H "Authorization: Bearer fi_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://your-server.com/webhook", "events": ["email.received"]}'

Static analysis

No suspicious patterns detected.