Back to skill

Security audit

Writing and reading

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it says, but it handles wallet and mailbox credentials while persisting tokens locally and shipping dependency versions flagged for security issues.

Review before installing. Use it only if you trust MoltMail/EtherMail with the agent mailbox, avoid importing a valuable wallet private key, prefer interactive passphrase entry over environment variables on shared systems, protect the ./state directory, and update vulnerable dependencies before using it for sensitive mail or account workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description advertises a broad external service for agent email, wallets, identity, and communications. The actual code chunk contains only a local cryptography helper module for encrypting and decrypting strings. It does not send email, manage inboxes, create wallets, handle payments, provision identities, integrate with external services, or expose the described agent infrastructure. While encryption could be a supporting detail in a larger system, this code chunk by itself does not substantively implement or reflect the declared primary purpose, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code chunk does not implement the broad advertised functionality around agent email, isolated identity, signup/confirmation handling, or communications. Instead, it performs a specific wallet-related action: loading auth and fetching earned coins. While coin handling is loosely adjacent to the wallet/payment theme in the description, the actual behavior shown is materially narrower and not accurately represented by the declared purpose. Therefore this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad platform for agent email, wallet, and identity infrastructure. The actual code chunk is much narrower: it authenticates, extracts userId, and outputs it as a referral code. This behavior is not representative of the described primary purpose and instead reflects a referral/account utility. While reading auth could be a supporting detail in a larger system, this specific code does not implement or directly demonstrate the advertised email, wallet, messaging, or payment capabilities. Therefore, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description promises a broad agent infrastructure layer centered on email plus wallet identity and related communications/payment capabilities. The supplied code does not implement those behaviors. It only performs local wallet setup and encrypted storage for an EtherMail-related account using a CLI prompt flow. While wallet creation/import is consistent with part of the description, the primary represented functionality—email infrastructure and agent identity services—is absent from this code chunk. This is a material description-versus-behavior mismatch, not just an omitted implementation detail.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins axios 1.13.5, and the supplied advisory set includes multiple high-severity issues affecting proxy handling and request behavior. In this skill’s context, axios is likely used for external API calls for email and wallet infrastructure, so SSRF, proxy bypass, credential leakage, or response tampering would be especially dangerous because the agent may handle secrets, confirmations, and payment-related traffic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
88% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection through unescaped multipart field names or filenames. If the skill uploads files or constructs multipart requests from agent-controlled or external input, this can enable request smuggling-style manipulation, malformed downstream parsing, or injection into HTTP payload boundaries.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
90% confidence
Finding

ws 8.17.1 is flagged for memory disclosure and memory exhaustion DoS issues. In a wallet- and messaging-related skill, websocket use can expose long-lived connections to untrusted peers or services, making denial of service or unintended data exposure more consequential for agent availability and possibly sensitive runtime data.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
89% confidence
Finding

The package allows installation of axios versions in the 1.13.x range, and the supplied analysis indicates a resolved version of axios 1.13.5 with multiple advisories, including SSRF and prototype-pollution-related risks. In a skill that handles email and external network interactions, a vulnerable HTTP client materially increases risk because untrusted URLs, proxy behavior, or crafted responses could be used to exfiltrate data, bypass network controls, or hijack request handling.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'enquirer' resembles popular package 'inquirer'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'enquirer' resembles popular package 'inquirer'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly tells users that a wallet passphrase can be supplied via an environment variable and that JWT auth material is stored locally, but it does not warn about the operational risks of those choices. Environment variables can be exposed through process listings, shell history, CI logs, or crash reports, and locally stored tokens may be recoverable by other local users, backups, or malware if not handled carefully.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares installable code and explicitly relies on environment-provided secret material (ETHERMAIL_PASSPHRASE), but it does not define an explicit tool/permission scope. In practice this weakens least-privilege guarantees and can cause an agent runtime to expose environment access or code execution capabilities without clear user-facing boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation guidance mixes precise cases with vague ones such as privacy interest and generic temp-email requests, which increases the chance the skill is invoked outside its intended scope. Because the skill can create identities, handle passphrases, authenticate to a remote service, and potentially involve wallet material, ambiguous activation raises the risk of unintended sensitive operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase 'Create an email account for me' is broad enough to capture generic user requests that may not imply consent to create a Web3-linked wallet-backed identity on a third-party service. In this skill's context, misrouting such requests is more dangerous because setup may lead users into generating or importing wallet credentials and storing authentication material locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill persists a bearer authentication token to a predictable local file under the project state directory. Even with file mode 0600, local token storage increases the risk of credential theft through local compromise, workspace leakage, backups, or accidental inclusion in artifacts, and possession of the token may allow unauthorized mailbox and account access until expiry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The sendEmail and replyToEmail functions post message bodies, recipients, subject lines, and HTML/text content to a remote service, but this file provides no confirmation prompt, user-visible logging, or comment/docstring warning that user email data will be transmitted. This is a safety-relevant network operation involving potentially sensitive user content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code silently consumes ETHERMAIL_PASSPHRASE from the process environment, which is a sensitive credential source. There is no confirmation prompt, logging, comment, or visible user-facing notice in this file that the skill may read credentials from environment variables.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Fetching email content also changes message state by automatically marking the message as read, which introduces a hidden side effect into what appears to be a read-only operation. In an agent setting, this can alter mailbox state, interfere with auditability or downstream workflows, and mislead users or other automations that rely on unread status to track unprocessed messages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script marks email as read immediately after retrieval without confirmation, warning, or caller control. In this skill's context, where AI agents may inspect inboxes autonomously, this can cause silent state changes that hide unread messages from humans, disrupt operational workflows, and make important messages appear already handled when they were only machine-fetched.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script obtains an authentication token and persists it via saveLoginToken without any visible safeguards in this file such as encryption, restrictive file permissions, expiration handling, or explicit operator consent. For an agent skill that provisions email and wallet-linked identity, a stolen token could let an attacker access the agent's mailbox/account and potentially abuse linked agent workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description emphasizes email addresses, crypto wallets, isolated identity, signup flows, forwarding, payments, and agent communication. The skill documentation additionally instructs use of referral attribution (afid), referral code retrieval, and EMC reward-balance queries, which are product-growth and rewards capabilities rather than clearly described identity/email operations.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
86% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. Because this package is a transitive dependency of axios, an attacker controlling or influencing redirects could cause bearer tokens, API keys, or session headers used by the agent to be sent to an attacker-controlled host.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"get-earned-coins": "ts-node scripts/getEarnedCoins.ts"
  },
  "dependencies": {
    "axios": "^1.13.4",
    "enquirer": "^2.4.1",
    "ethers": "^6.16.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 19)May include surrounding context.

json
},
  "dependencies": {
    "axios": "^1.13.4",
    "enquirer": "^2.4.1",
    "ethers": "^6.16.0"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"dependencies": {
    "axios": "^1.13.4",
    "enquirer": "^2.4.1",
    "ethers": "^6.16.0"
  },
  "devDependencies": {
    "@types/node": "^25.2.0",

Static analysis

Detected: suspicious.potential_exfiltration

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
lib/ethermail.ts:112