Back to skill

Security audit

163邮箱助手免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a 163 email helper, but it asks the agent to handle mailbox credentials and destructive email actions without enough confirmation or scoping guidance.

Install only if you are comfortable giving an agent access to your 163 mailbox through a client authorization code. Use a dedicated or low-risk mailbox where possible, store the auth code securely, confirm exact message IDs before delete or move operations, and download attachments only to a controlled folder after checking that the sender and file are trusted.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger description is overly broad and can cause the skill to activate for loosely related communication or automation tasks beyond basic 163 email operations. In an agent environment with `exec`, `read`, and `write` available, over-triggering increases the chance the agent will apply this skill in the wrong context and perform unintended email or local file actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The 'capability coverage' section expands the skill's implied scope with vague keywords like messaging, notification pushing, SMS, and communication integration, which are not clearly supported by the documented implementation. This ambiguity can mislead an agent into using the skill for out-of-scope tasks and, given the tool permissions, may result in inappropriate command execution or mishandling of user data.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents destructive and sensitive operations such as deleting mail, deleting folders, moving messages, and downloading attachments locally without requiring confirmation or warning about irreversible effects and trust boundaries. In an autonomous agent setting, this increases the risk of accidental data loss, unsafe attachment handling, or writing sensitive content to local disk without informed user consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.