Back to skill

Security audit

iGPT email ask

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed iGPT email-analysis skill that sends user questions and connected email context to iGPT, with no hidden persistence, destructive actions, or unrelated behavior found.

Install only if you trust iGPT to process the connected mailbox data. Use a least-privileged or approved email account where possible, review OAuth consent before authorizing, keep the API key protected, and prefer a pinned reviewed `igptai` version in managed environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:38
Finding

Unpinned Third-Party SDK Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38–48
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

markdown
## Prerequisites

1. An iGPT API key (get one at https://igpt.ai/hub/apikeys/)
2. A connected email datasource -- the user must have completed OAuth authorization via `connectors/authorize` before ask will return results. You can check connection status with `datasources.list()`.
3. Python >= 3.8 with the `igptai` package installed

## Setup

```bash
pip install igptai
text

### Technical Analysis

The setup instructions install the latest available release of the third-party `igptai` package without specifying an exact version or verifying an integrity hash. The audited project contains no lockfile, hash-pinned requirements file, or vendored implementation that would make the installed dependency reproducible and reviewable.

Consequently, the code executed by users may differ from the code that existed when this skill was reviewed. Installation hooks or imported package code can execute with the privileges of the user running `pip` or the skill. This finding concerns mutable dependency resolution; the audit found no evidence that the package is currently malicious.

### Attack Path

1. An attacker compromises the package publisher account, package repository, release process, or another relevant supply-chain component.
2. The attacker publishes a malicious or compromised release under the expected package name.
3. A user follows the documented `pip install igptai` command.
4. Package resolution retrieves the mutable latest release because no exact version or hash is required.
5. Malicious installation hooks or package code execute when the dependency is installed or imported.
6. The payload operates with the installing user's privileges and may attempt to access environment variables or data handled by the process.

### Impact Assessment

Successful e
...[truncated 705 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the SDK to an exact, reviewed version rather than installing an unconstrained latest release:
    text
    igptai==<reviewed-version>
    
  2. Record cryptographic hashes in a requirements file and enforce them:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Commit a reproducible lockfile or hash-pinned requirements file to the skill package.
  4. Install only from the expected package index over TLS and document the verified package publisher and source repository.
  5. Review dependency updates before changing the pinned version, including package provenance, release changes, transitive dependencies, and installation hooks.
  6. Run the SDK in a least-privileged, isolated environment with access only to the required API key and data.
  7. Avoid exposing unrelated credentials or sensitive environment variables to the process using the dependency.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This skill explicitly transmits user prompts and email-derived context to a remote third-party API endpoint (api.igpt.ai) for processing. Even though this is the stated purpose of the skill and the transmission is disclosed, it still creates a real data exfiltration boundary because potentially sensitive email content leaves the local agent environment and depends on vendor-side security and privacy controls.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
This skill communicates exclusively with:

- `https://api.igpt.ai/v1/recall/ask/` -- the reasoning endpoint
- `https://api.igpt.ai/v1/connectors/authorize/` -- only during initial datasource connection setup
- `https://api.igpt.ai/v1/datasources/list/` -- to check connection status

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The documented use of connectors/authorize means the skill initiates OAuth-based linkage to external email data through a remote service, extending trust to an outside provider. This is not inherently malicious, but it is a genuine security-relevant external transmission path because mailbox metadata/content and authorization context may be exposed to a third-party platform.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
This skill communicates exclusively with:

- `https://api.igpt.ai/v1/recall/ask/` -- the reasoning endpoint
- `https://api.igpt.ai/v1/connectors/authorize/` -- only during initial datasource connection setup
- `https://api.igpt.ai/v1/datasources/list/` -- to check connection status

No other external endpoints are contacted. No data is sent to any third-party service. The `igptai` PyPI package source is available at https://github.com/igptai/igpt-python.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The datasources/list and surrounding documented workflow confirm ongoing communication with a remote service that brokers access to user email data. In the context of an email-analysis skill, this makes the finding more significant because the content being reasoned over can include confidential business, legal, or personal communications, so any off-platform transmission materially increases exposure.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
- `https://api.igpt.ai/v1/recall/ask/` -- the reasoning endpoint
- `https://api.igpt.ai/v1/connectors/authorize/` -- only during initial datasource connection setup
- `https://api.igpt.ai/v1/datasources/list/` -- to check connection status

No other external endpoints are contacted. No data is sent to any third-party service. The `igptai` PyPI package source is available at https://github.com/igptai/igpt-python.

Static analysis

No suspicious patterns detected.