Back to skill

Security audit

Agently Mail

Security checks for vulnerabilities and agentic risk

Overview

This mail skill is mostly coherent, but it asks users to install mutable global tools and then grants persistent mailbox access, so it belongs in Review rather than automatic trust.

Install only if you trust Tencent's mail CLI distribution and are comfortable granting persistent mailbox access on this machine. Prefer pinned, reviewed package versions, avoid elevated shells, review OAuth permissions carefully, and use the listed logout command when access is no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned Third-Party Packages Are Installed and Executed Globally

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25-31
Vulnerability Type: Unpinned dependency installation and execution
Risk Level: Medium

Vulnerable Code

bash
npm install -g @tencent-qqmail/agently-cli

Step 2 — Install/update the skill:

bash
npx skills add Tencent/AgentlyMail -g -y

Technical Analysis

The installation instructions resolve and execute third-party npm packages without pinning exact versions or verifying package integrity.

npm install -g @tencent-qqmail/agently-cli installs the currently resolved package release globally. Depending on npm configuration and package contents, installation can execute package lifecycle scripts with the privileges of the invoking user.

The npx skills ... -y command similarly resolves and executes the skills command while automatically accepting installation prompts. The -y option reduces the opportunity for the user to inspect or reject an unexpected package resolution. Neither command uses an exact reviewed version, lockfile, cryptographic integrity value, or locally audited artifact.

The external package implementations are not included in this project and therefore could not be reviewed as part of this audit. The issue is an unsafe supply-chain boundary rather than evidence that the referenced packages are currently malicious.

Attack Path

  1. An attacker compromises a referenced npm package, its publisher account, or its release pipeline.
  2. Alternatively, an unexpected or malicious future package version is published under a dependency resolved by one of the commands.
  3. A user follows the skill instructions and runs the unpinned global installation or npx command.
  4. npm retrieves the mutable package version available at execution time.
  5. Malicious package code or lifecycle scripts execute with the privileges of the invoking user.
  6. The malicious code can access resources available to that user, ...[truncated 921 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every executable package to a reviewed exact version, for example:

    bash
    npm install -g @tencent-qqmail/agently-cli@<reviewed-version>
    npx --package=skills@<reviewed-version> skills add Tencent/AgentlyMail -g
    
  2. Remove automatic approval through -y so users can review unexpected package installation prompts.

  3. Prefer a project-local installation governed by a committed lockfile instead of modifying global package state.

  4. Verify package provenance, signatures, checksums, and npm registry configuration before installation. Consider using npm provenance attestations where available.

  5. Audit package lifecycle scripts and published package contents before approving version updates.

  6. Execute installation with a non-privileged account and avoid sudo or administrator shells.

  7. Use an allowlisted internal registry or mirror containing reviewed package artifacts for security-sensitive deployments.

  8. Document an explicit version-update and security-review process instead of always installing the latest available release.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description says to use this skill whenever the user needs any mail-related operation, which is an overly broad trigger. Broad auto-invocation criteria can cause the agent to route sensitive conversations into a high-privilege mail skill unnecessarily, increasing the chance of unintended mailbox access or email-sending actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata and instructions force Chinese output without checking the user's preferred language. This can mislead users during consent and authorization flows, especially when precise understanding is required for OAuth and email actions, reducing informed consent and increasing the risk of user error.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill instructs use of npx skills add Tencent/AgentlyMail -g -y without pinning a specific version or immutable source reference. That allows future upstream changes or a compromised package/registry response to alter what gets installed, creating a supply-chain risk for anyone following the setup instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill requires a fixed Chinese authorization prompt with no language choice during OAuth handoff. In a security-sensitive authorization step, forcing a single language can cause users to misunderstand what link they are opening or what authorization they are granting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The verification step mandates a Chinese-only success message and forbids any extra output. That rigidity can prevent the agent from communicating clearly in the user's language about which account was authorized, weakening transparency around a sensitive credential-binding action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.