Back to skill

Security audit

Operate company email

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Banger email-operations integration with disclosed external MCP access and many user-confirmation boundaries, though it can handle sensitive company email data.

Install this only if you intend to connect an agent to your Banger workspace. Review Banger's authorization screen and workspace scope carefully, since the skill can read and modify company email state, contacts, domains, broadcasts, journeys, and related setup through Banger. Use extra care before asking it to send mail, import contacts, create credentials, or change DNS-related settings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
Use Banger as the governed system of record. Humans, Banger, and external agents must see and modify the same workspace state.

If no `banger_*` tools are available, the Banger MCP server is not connected yet. Ask the user to add the remote server `https://api.bangermail.com/mcp` (Streamable HTTP, OAuth sign-in in the browser; no API key) in their client's MCP settings, then sign in. Setup guides per client: https://bangermail.com/banger-mcp/. Never ask for a password or token in chat.

Use the product's canonical vocabulary in every user-facing response: **Mailboxes**, **Journeys**, **Broadcast**, **Product email**, **Approvals**, and **Logs**. A Journey is any automated email flow, whether it has one step or many. Do not expose the retired Autopilot, automation, sequence, campaign, or transactional-screen names. If an older client invokes a compatibility alias, describe the result with the canonical term.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- **Setup has three parts:** connect the AI, Brand (website, then email style), and Your domain. The person may have done some in the Banger web app; continue only what is unfinished. `setup.missing` lists what was skipped or never done; offer those again only when relevant, never as a nag.
- **Brand** comes first. Reuse known context, or ask only for `website_url` and `discover_brand`; without a website, ask for brand materials, otherwise keep defaults. The brand step also picks the email style: lead with "Your brand" (Clarity in their own fonts and colors), then offer the seven presets with their one-line descriptions. Where previews render, show the welcome starter (`banger_list_starters` with `id=welcome` and a style, then `banger_preview_email_design`). Save the pick as `data.brand.email_style` with `save_business`; with no preference keep `brand` and say so. `save_business` accepts an empty object; do not require a form or invent goals. Use `skip_business` only on an explicit skip.
- **After setup**, say in two or three lines what they can ask you to do next: create mailboxes such as hello@ or support@ and answer new mail, import contacts and draft a Broadcast, build a Journey such as a welcome series, or make a signup form; sending to people outside the workspace needs the verified domain. Create a draft only if they ask for one: then use the normal product tools (templates and Broadcasts with their own tools; full Journeys with `banger_create_journey` / `banger_update_journey`), preserving the requested language, emails, timing, content and layout, and show each saved email with `banger_show_email_preview`.
- **Your domain** is one lesson with three phases: Connect, Verify, Add inboxes. Connect: ask only for the domain, call `choose_identity` without addresses, then `setup_sending`. When the root domain already has email, Banger keeps it and picks a checked free subdomain (`progress.domain_options.defaulted`): say so in one line using its `message` ("Google 
...[truncated 26 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
## Integrations and credentials

- Credentials never pass through chat. Never ask the user to paste a token, secret URL, or code into chat.
- `banger_create_incoming_webhook` and `banger_create_api_key` are not idempotent: inspect `banger_list_webhooks` or `banger_list_api_keys` before retrying an uncertain result. Reopen an existing incoming webhook's credentials with `banger_get_incoming_webhook_credentials` instead of recreating it; revoke an API key whose token was lost. Without an MCP Apps host, send the user to Banger's Webhooks or API keys page.
- Check `banger_list_webhooks` evidence before claiming an integration works. `banger_test_webhook` queues a test to an outbound endpoint; read the result from `banger_list_webhooks`. Confirm with the user before disabling a webhook with `banger_set_webhook_status`.
- Revoke a connected agent (`banger_revoke_connected_agent`, identifiers from `banger_list_connected_agents`) only when the user asks.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

This skill is configured to communicate with an external MCP endpoint over HTTP-based transport, which creates a real data egress path to a third-party service. In context, the skill manages company email operations, so prompts, mailbox data, recipient lists, or configuration details could be transmitted externally; combined with implicit invocation, this increases the chance of unintentional disclosure.

Content

Scanner excerpt · agents/openai.yaml (reported line 14)May include surrounding context.

yaml
value: "banger"
      description: "Banger company email operating system"
      transport: "streamable_http"
      url: "https://api.bangermail.com/mcp"
policy:
  allow_implicit_invocation: true

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation with no visible activation constraints, so it may be triggered automatically from broad user context rather than explicit user intent. Because this skill operates a company email system with capabilities like sending mail, reading mailboxes, and managing domains or audiences, unintended invocation could cause sensitive data exposure or unauthorized email actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.