Back to skill

Security audit

email-163

Security checks for vulnerabilities and agentic risk

Overview

The skill is an email-management helper, but it handles mailbox credentials and supports bulk sending, deleting, and scheduled cleanup without enough safety controls.

Review before installing. Only use this with mailboxes you are allowed to automate, keep authorization codes out of shared files and repositories, prefer environment variables or a secret manager, restrict permissions on any config files, and require dry-run/preview plus explicit approval before bulk sends, deletes, moves, archives, or scheduled cleanup tasks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:267
Finding

Plaintext Storage of Reusable Mailbox Authorization Codes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 267–273 and 303–311
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

Vulnerable Code

The general configuration example stores a reusable mailbox authorization code in a plaintext JSON field:

json
{
  "email": "enterprise@163.com",
  "password": "your_auth_code",
  "imap_server": "imap.163.com",
  "imap_port": 993,
  "smtp_server": "smtp.163.com",
  "smtp_port": 465,
  "pro": {

The multi-account setup explicitly instructs users to create another plaintext credential file:

bash
mkdir -p ~/.config/email-163-tool/accounts
cat > ~/.config/email-163-tool/accounts/finance.json << 'EOF'
{
  "name": "财务部邮箱",
  "email": "finance@company.com",
  "password": "finance_auth_code"
}
EOF
email-163-tool accounts list

Technical Analysis

The documented setup places reusable 163 mailbox authorization codes directly in JSON configuration files. The multi-account command writes such a file without setting restrictive permissions on either the account directory or the resulting file. Consequently, access depends on the user's umask and surrounding system configuration.

Although the document states elsewhere that encrypted storage is supported, the actionable setup instructions do not use a keychain, secret manager, environment-variable reference, or encrypted credential store. They also do not enforce owner-only permissions. Users following these instructions with real credentials may therefore leave mailbox secrets exposed to other local accounts, compromised processes running with filesystem access, insecure backups, support bundles, or accidental configuration-file disclosure.

Attack Path

  1. A user follows the documented multi-account setup.
  2. The user replaces finance_auth_code with a genuine reusable mailbox authorization code.
  3. The shell writes that code in plaintext to ~/.config/email-163-tool/accounts/finance.json.
  4. The file receives ...[truncated 1277 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store authorization codes in an operating-system keychain, enterprise secret manager, or encrypted credential store. Configuration files should contain only secret identifiers or runtime references.
  2. Prefer runtime secret injection through a protected mechanism rather than placing credentials directly in JSON.
  3. If file-based storage is unavoidable, create the directory and file with owner-only permissions:
bash
install -d -m 700 ~/.config/email-163-tool/accounts
umask 077
install -m 600 /dev/null ~/.config/email-163-tool/accounts/finance.json
  1. Validate permissions before loading a credential file and refuse to proceed when it is group-readable or world-readable.
  2. Update examples to use an explicit placeholder such as ${EMAIL_163_AUTH_CODE} and clearly warn users never to commit or share populated configuration files.
  3. Exclude credential files from version control, diagnostics, support bundles, logs, and unencrypted backups.
  4. Document authorization-code rotation and immediate revocation procedures for suspected exposure.
  5. Apply least privilege where the provider supports scoped or application-specific credentials, and use separate credentials for each mailbox.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill supports bulk sending with variable substitution using recipient CSV data that may contain personal or sensitive information, yet it lacks explicit privacy warnings, data-minimization guidance, or user-consent safeguards. In practice this can lead to unintended disclosure of employee data, misdirected emails, or mass transmission of sensitive content through networked mail infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents destructive operations such as bulk delete and scheduled cleanup with no explicit confirmation, dry-run requirement, recycle/undo flow, or high-visibility warning. In an agent context with exec capability, this raises the risk of accidental or over-broad deletion of user email, especially when commands are automated or parameterized.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The documentation instructs users to persist multiple mailbox account credentials, including authorization codes, in plaintext JSON files under a predictable path in the home directory. If local compromise, backup leakage, or over-broad file permissions occur, attackers could recover these credentials and gain long-lived access to multiple mail accounts.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

多账户配置

为每个邮箱账户创建独立配置文件:

bash
mkdir -p ~/.config/email-163-tool/accounts
cat > ~/.config/email-163-tool/accounts/finance.json << 'EOF'
{
  "name": "财务部邮箱",

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L319-L357将技能输出定义为“overall_grade”“代码风格”“安全合规”等审查评分结果,这与前文持续描述的邮件发送、搜索、归档和调度功能不一致。该文档不是简单遗漏实现细节,而是主动把技能说成一个评审/打分类工具,和邮箱助手定位形成直接冲突。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L380-L384明确说明本工具使用163邮箱授权码认证且“无需额外 API Key”,但L453-L454、L468-L470、L479随后又把API密钥配置、API认证失败和API调用写成通用使用步骤。该矛盾会误导使用者提供与技能目标无关的凭证,属于文档意图与实际认证模型的直接冲突。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

L443-L447将技能特性概括为“API集成”“调用外部服务并处理响应”,这是比163邮箱收发、搜索、归档、调度更宽泛的外部服务调用能力。清单描述聚焦163邮箱企业管理,并未声明面向任意外部API的集成能力,因此这里表现出技能范围被扩展。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The display name, summaries, and nearly all user-facing documentation are presented in Chinese, with no indication that users can choose another language or that the skill is intentionally limited to a China-specific audience for compliance reasons. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.