Back to skill

Security audit

163邮箱助手专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent 163 email management helper, but it needs review because it enables bulk and scheduled mailbox changes with broad command execution and limited mandatory safeguards.

Review this skill before installing. Use it only with configured 163 mailboxes you control, require dry-run or preview for bulk actions, confirm before sending or deleting at scale, and avoid enabling scheduled deletion unless scopes, logs, and recovery procedures are clear.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill explicitly advertises general command execution capability and also declares the 'exec' tool in metadata, which creates a real risk of the agent being induced to run shell commands outside the narrow email-management purpose. In an agent setting, broad exec access materially increases the blast radius of prompt injection, unsafe automation, and unintended local/system actions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition is broad enough to match generic requests about messaging, notifications, SMS, or communications integration, which can cause the skill to activate outside its intended 163-email scope. Overbroad activation increases the chance that the agent applies powerful mail and exec-capable behaviors in the wrong context, leading to mistaken actions or unnecessary access to sensitive data.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The core capability list includes batch delete/move, bulk marking, archiving, and multi-account handling without prominent confirmation or safety guidance. In an enterprise mail context, these operations can affect large volumes of sensitive communications, so missing guardrails can lead to accidental data loss, privacy violations, or mass mailbox changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The scheduled cleanup example automates mailbox deletion using a cron-triggered action pipeline, but it does not include an explicit warning about unattended destructive execution. Because this runs periodically and may operate without human review, a bad query, changed mailbox contents, or injected parameters could repeatedly delete legitimate messages at scale.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.