Back to skill

Security audit

Clank Email Monitor

Security checks for vulnerabilities and agentic risk

Overview

This is a simple email-monitoring skill description with expected but sensitive email credential handling that users should secure carefully.

Before installing, treat the configured mailbox credentials as sensitive: use app-specific or narrowly scoped credentials when possible, keep `~/.email-monitor/config.json` out of source control and backups, restrict its permissions to the current user, and review any implementation before enabling background monitoring or auto-replies.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

Plaintext Storage of Email API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39-49
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

The documented configuration instructs users to store an email API key directly in ~/.email-monitor/config.json:

json
{
  "inboxes": [
    {
      "name": "work",
      "provider": "agentmail",
      "api_key": "your_key",
      "inbox_id": "you@agentmail.to"
    }
  ],

Technical Analysis

API credentials are sensitive authentication material. The documented configuration embeds the API key directly in a plaintext JSON file without requiring restrictive file permissions, validating file ownership, referencing an operating-system credential store, or offering an environment-based secret mechanism.

Although the example contains only the placeholder value your_key, users following these instructions would replace it with a real credential. The resulting file may then be readable by other local accounts or processes if it is created with permissive permissions. The credential may also leak through backups, support bundles, home-directory synchronization, or accidental source-control inclusion.

The artifact contains only documentation, so the implementation's actual permission handling and credential-loading behavior could not be verified.

Attack Path

  1. A user follows the documented setup instructions and places a valid AgentMail API key or equivalent mailbox credential in ~/.email-monitor/config.json.
  2. The configuration file is created with permissions that allow an unauthorized local user or process to read it, or the file is copied into an exposed backup or repository.
  3. The attacker extracts the plaintext credential from the JSON file.
  4. The attacker uses the credential against the associated email provider's API.
  5. The attacker gains whatever mailbox operations and data access are authorized by that credential.

Impact Ass

...[truncated 563 chars]

Remediation
View remediation

Remediation Suggestions

  • Store API keys in an operating-system credential manager or dedicated secret-management service rather than directly in the JSON configuration.
  • If file-based configuration is required, allow the JSON file to reference an environment variable or secret identifier instead of containing the secret value.
  • Create the configuration file with permission mode 0600 and verify that it is owned by the current user before reading credentials from it.
  • Refuse to load credentials from files that are group-readable, world-readable, or owned by another user.
  • Add explicit documentation warning users not to commit the configuration file to source control, include it in support bundles, or place it in insecure synchronized storage.
  • Recommend narrowly scoped, revocable credentials and document a credential-rotation procedure for suspected exposure.
  • Provide a .gitignore example covering .email-monitor/config.json when project-local configuration is supported.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is explicitly designed to monitor email inboxes, process message content, and store authentication material, but the description and feature list do not warn users about the scope of mailbox access, credential handling, or the sensitivity of monitored communications. In this context, missing privacy and data-access disclosure can cause users to grant broad access without understanding the exposure of email content, contacts, and credentials.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The documentation instructs users to create a persistent configuration file under the home directory that contains sensitive mailbox credentials such as API keys and inbox identifiers. Storing secrets in a long-lived plaintext file increases the risk of credential exposure through local compromise, backups, misconfigured permissions, or accidental inclusion in logs or source control.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Configuration

Create ~/.email-monitor/config.json:

json
{

Static analysis

No suspicious patterns detected.