Back to skill

Security audit

VexPath Skill Pack

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a business email automation skill, but it needs review because it handles mailbox credentials, persistent inbox monitoring, workspace behavior files, and under-disclosed roofing lead-enrichment/outreach tools.

Install only after narrowing what you actually need. Treat this as a high-access business automation pack: use app passwords or OAuth where possible, avoid passing passwords on the command line, inspect who can read the workspace files, and keep outbound sending approval-only. Remove or disable the roofing estimator and cold-outreach scripts unless you explicitly need address enrichment and have a lawful basis to process and contact those leads.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (37)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The guide explicitly says plaintext password storage is acceptable for local/private setups while the example uses `passwd.cmd = "echo 'your-password'"`, which still exposes the secret in configuration and process-invoked command strings. This normalizes insecure credential handling and can lead to password disclosure via config file access, backups, shell history reproduction, or local inspection by other users/processes.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The onboarding flow expands into collecting calendar access methods and recording calendar connection details, which goes beyond minimal email triage needs and increases the scope of sensitive data handled by the skill. In this context, broadening access to adjacent systems without clear necessity or consent boundaries raises the chance of over-collection, misuse, or accidental disclosure.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Directing the agent to install additional control files such as SOUL.md and HEARTBEAT.md introduces persistence and behavioral modification mechanisms not clearly justified by the stated onboarding purpose. These files can silently alter future agent behavior or monitoring scope, creating an unnecessary trust and integrity risk in the workspace.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
This section operationalizes mass cold-outreach using public records and storm-event targeting, which expands the skill from email triage into lead generation and solicitation. In an agentic context, this can enable unsolicited contact campaigns at scale, increasing spam, privacy, and regulatory risk even if the content mentions CAN-SPAM compliance.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The file includes detailed storm-damage solicitation playbooks and ready-to-send cold email templates tailored to homeowners, which goes beyond the stated business-operations/email-triage scope. This makes the skill more dangerous because it provides turnkey instructions for targeted outreach based on inferred property conditions, facilitating spammy or manipulative campaigns.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The module performs specialized roofing estimation and property-analysis workflows that are materially different from the manifest's generic operations/email-automation description. Scope mismatch is risky because operators may enable the skill without realizing it can perform geocoding, property analysis, and quote generation against third-party data sources.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The script expands an email/workflow automation skill into property intelligence gathering by requiring a Google Maps API key and invoking a roof-estimation workflow for physical addresses. That data collection is not aligned with the stated skill purpose and creates a privacy-sensitive surveillance/enrichment capability that can be used to profile homeowners for unsolicited outreach.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file's behavior materially diverges from the advertised skill scope: instead of inbox triage or workflow support, it generates cold-sales emails from inferred roof damage/replacement estimates. This mismatch is dangerous because users may install or trust the skill for benign office automation while it actually enables targeted solicitation using sensitive property analysis.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
This script implements geocoding and roof-estimation functionality that is materially unrelated to the declared skill purpose of email triage, workflow automation, and business operations. Such hidden or mismatched capabilities are dangerous because they can bypass user and reviewer expectations, enabling undisclosed data processing or repurposing of the skill for property intelligence collection.

Context-Inappropriate Capability

High
Confidence
91% confidence
Finding
The script sends user-supplied addresses to Google Maps Geocoding and Solar APIs to derive building and roof characteristics, but this capability is not justified by the stated business-operations use case. In the context of an ostensibly email/ops automation skill, this creates a hidden external-data exfiltration and profiling path that could be abused for unauthorized property analysis.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README promotes automated email monitoring, structured extraction, and CRM synchronization without any mention of consent, data minimization, access controls, retention, or handling of sensitive information. In a skill specifically designed for inbox triage and business operations, this omission can normalize unsafe deployment practices that expose personal, confidential, or regulated data.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation description is broad enough to match many ordinary business requests, which can cause the skill to be loaded in contexts where users did not intend to grant inbox, workflow, or automation-related powers. In this skill, that broad trigger surface is more dangerous because the instructions include credential handling, inbox retrieval, script execution, and workspace file modification.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The 'When to Use This Skill' section enumerates many common scenarios but provides no exclusion conditions, safety gates, or requirement for user confirmation before accessing systems. This can lead to accidental activation in sensitive contexts such as inbox processing or client operations, where the skill may prompt for credentials or perform changes without sufficiently explicit consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The scripts section instructs running email setup and triage operations, including use of credentials and pulling inbox contents, but does not present a prominent warning about sensitive data exposure, retention, third-party access, or the consequences of granting mailbox access. Because email often contains confidential business and personal data, this omission materially increases privacy and security risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The first-time setup checklist explicitly tells the user to run setup with email credentials and then pull inbox data, yet it lacks an upfront privacy, authorization, and system-impact warning. In context, this is especially risky because the checklist operationalizes credential use and mailbox retrieval as routine setup steps, normalizing access to highly sensitive communications without adequate safeguards.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The heartbeat workflow continuously reads inbox contents and persists derived data into local memory files, but it provides no explicit privacy boundaries, consent requirements, retention limits, or guidance on handling sensitive personal or business information. In an email-triage skill, this is especially risky because messages may contain credentials, financial data, legal matters, or other regulated content that could be unnecessarily stored, exposed to other components, or retained longer than intended.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file explicitly instructs the agent to collect and persist a client's business email address, communication tooling, CRM usage, and operational pain points into `TOOLS.md`, but provides no minimization, consent, retention, or access-control guidance. In an agent skill that configures inbox monitoring and automation, this creates a real privacy and data-governance risk because sensitive business contact and workflow information may be stored in a broadly accessible workspace artifact.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill states that VEX will monitor and triage inboxes and 'route and respond' across business communication channels, yet it does not warn about privacy implications, authorization boundaries, or the operational risks of automated actions. In this context, the absence of guardrails is security-relevant because the skill is designed to act on real communications, so unclear consent and insufficient approval controls could lead to unauthorized access, disclosure, or unintended outbound messaging.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guidance explicitly recommends mining client emails, intake forms, sales calls, consultations, and project outcomes for content ideas without any guardrails around confidentiality, consent, anonymization, or contractual/privacy restrictions. In a business-operations skill that handles inboxes, client communication, and CRM-related workflows, this creates a realistic risk of disclosing sensitive client information or repurposing private communications into marketing content without authorization.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document directs systematic extraction of sender identity, message contents, urgency, and business context, then routes that data into CRM, calendar, sheets, and reporting systems, but it does not define consent, minimization, retention, access control, or handling rules for sensitive email content. In an email-triage skill, this materially increases privacy and compliance risk because personal and potentially confidential data may be copied across multiple systems automatically.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The reference explicitly instructs storing personally identifiable information such as contact names, email addresses, subjects, and workflow history in a local JSON file without any retention limits, access controls, encryption guidance, or privacy notice. In an email-automation skill, this increases the chance of unauthorized disclosure through local compromise, overbroad access by other components, backups, logs, or accidental sharing of the memory directory.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
Passing an email password directly on the shell command line can expose it through shell history, process listings, audit logs, terminal recording, and CI/job logs. Because this skill is for email triage and operations automation, it is likely to be used in real business environments where credential leakage could grant mailbox access and enable account takeover or sensitive email compromise.

Missing User Warnings

High
Confidence
99% confidence
Finding
The manual configuration embeds the password via a literal `echo 'your-password'`, which is effectively hardcoded secret storage and may be recoverable from config files, dotfile sync, backups, screenshots, or local forensic inspection. The surrounding note downplays the risk, increasing the chance that users will adopt an insecure pattern for production-adjacent business email accounts.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The instructions ask the user for an email address, display name, and app password, then direct execution of setup and triage scripts without any disclosure about how credentials are handled, where they are stored, or that inbox contents will be accessed. In an email operations skill, this is especially risky because the scripts may gain broad access to a sensitive mailbox and process personal or business communications without informed consent safeguards.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Storing calendar connection details and business/contact preferences in TOOLS.md creates a privacy risk because it encourages persistent recording of potentially sensitive operational data in a general workspace file without warning or access controls. Even if not overtly malicious, this design normalizes data retention that could later be exposed to other tools, users, or prompts.

Static analysis

No suspicious patterns detected.