Back to skill

Security audit

.Imap Smtp Email.Disabled.20260401 113327

Security checks for vulnerabilities and agentic risk

Overview

This email skill does what it claims, but its mailbox and file access have security weaknesses users should review before installing.

Install only if you are comfortable granting the skill access to the configured mail accounts and selected local directories. Use app-specific passwords, keep certificate verification enabled, restrict ALLOWED_READ_DIRS and ALLOWED_WRITE_DIRS to dedicated folders, avoid acting on instructions found inside emails without independent confirmation, and prefer a release with pinned dependencies plus stronger TLS and symlink-safe attachment writes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/imap.js:14
Finding

Attachment download write allowlist can be bypassed through symbolic links

Content
View full analysis
path.resolve(d.replace(/^~/, os.homedir())) ); const allowed = allowedDirs.some(dir => resolved === dir || resolved.startsWith(dir + path.sep) ); if (!allowed) { throw new Error(`Access denied: '${dirPath}' is outside allowed write directories`); } return resolved; } ``` ```javascript // Create output directory if it doesn't exist const resolvedDir = validateWritePath(outputDir); if (!fs.existsSync(resolvedDir)) { fs.mkdirSync(resolvedDir, { recursive: true }); } const downloaded = []; for (const attachment of parsed.attachments) { // If specificFilename is provided, only download matching attachment if (specificFilename && attachment.filename !== specificFilename) { continue; } if (attachment.content) { const filePath = path.join(resolvedDir, sanitizeFilename(attachment.filename)); fs.writeFileSync(filePath, attachment.content); ``` ### Technical Analysis The write allowlist compares only lexically resolved paths. `path.resolve()` normalizes path components but does not resolve symbolic links. Consequently, a path can appear to be beneath an allowed directory while its actual filesystem destination is outside that directory. Although `sanitizeFilename()` prevents direct filename traversal using `../`, it does not protect against a symbolic link in the destination path. `fs.writeFileSync()` follows symbolic links and overwrites an existing destination by default. ### Attack Path ...[truncated 1175 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/smtp.js:69
Finding

SMTP credentials may be transmitted without mandatory TLS

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/imap.js:181
Finding

Untrusted email content is returned directly to the Agent without trust-boundary controls

Content
View full analysis
]*>/g, '') : ''), attachments: parsed.attachments?.map((a) => ({ filename: a.filename, contentType: a.contentType, size: a.size, content: includeAttachments ? a.content : undefined, cid: a.cid, })), }; } ``` ```javascript default: console.error('Unknown command:', command); console.error('Available commands: check, fetch, download, search, mark-read, mark-unread, list-mailboxes, list-accounts'); process.exit(1); } console.log(JSON.stringify(result, null, 2)); } catch (err) { console.error('Error:', err.message); process.exit(1); } } ``` ### Technical Analysis Email sender, subject, body, and HTML fields are controlled by external message senders. The Skill returns these fields verbatim in its JSON output without marking them as untrusted, isolating them from instructions, or warning the consuming Agent not to execute directives embedded in the message. In an AI Agent environment, this creates an indirect prompt-injection channel. An attacker can place natural-language instructions in an email that attempt to override the user's objective, request disclosure of accessible information, or direct the Agent to invoke email and filesystem operations. HTML is also returned without sanitization. While it is not ...[truncated 1285 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:11
Finding

Dependencies are installed from mutable version ranges without a lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code accurately covers much of the declared IMAP functionality: checking unread/new mail, fetching message content, searching, marking read/unread, mailbox listing, and some multi-account awareness via account listing/config. However, the declared description prominently includes sending email via SMTP and sending emails with attachments, but this code chunk contains no SMTP logic and no outbound email sending. Additionally, the code includes a concrete capability to download and write attachments to local directories, which is related to email handling but not explicitly stated in the description. Because missing declared SMTP/send behavior is material, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a combined IMAP/SMTP email skill with both read and write mailbox operations. This code chunk is an SMTP CLI only. It can send email, optionally load subject/body/HTML from local files, attach local files subject to directory restrictions, test the SMTP connection by sending a test message, and list configured accounts. There is no code here for connecting to an IMAP server, reading inbox contents, searching folders, or updating message read/unread status. Therefore the actual behavior is materially narrower and different from the declared description. The extra list-accounts/config display behavior is minor but also not mentioned in the declared purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
node scripts/imap.js --account work check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 229)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

md
node scripts/smtp.js --account work send --to foo@bar.com --subject Hi --body Hello

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.js (reported line 9)May include surrounding context.

js
const dotenv = require('dotenv');

// Config file locations
const PRIMARY_ENV_PATH = path.join(os.homedir(), '.config', 'imap-smtp-email', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

// Find the .env file: primary location first, then fallback

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.js (reported line 10)May include surrounding context.

js
const dotenv = require('dotenv');

// Config file locations
const PRIMARY_ENV_PATH = path.join(os.homedir(), '.config', 'imap-smtp-email', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

// Find the .env file: primary location first, then fallback

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/imap.js (reported line 95)May include surrounding context.

js
const dotenv = require('dotenv');

// Config file locations
const PRIMARY_ENV_PATH = path.join(os.homedir(), '.config', 'imap-smtp-email', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

// Find the .env file: primary location first, then fallback

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/smtp.js (reported line 67)May include surrounding context.

js
const dotenv = require('dotenv');

// Config file locations
const PRIMARY_ENV_PATH = path.join(os.homedir(), '.config', 'imap-smtp-email', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

// Find the .env file: primary location first, then fallback

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.js (reported line 12)May include surrounding context.

js
const PRIMARY_ENV_PATH = path.join(os.homedir(), '.config', 'imap-smtp-email', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

// Find the .env file: primary location first, then fallback
function findEnvPath() {
  if (fs.existsSync(PRIMARY_ENV_PATH)) return PRIMARY_ENV_PATH;
  if (fs.existsSync(FALLBACK_ENV_PATH)) return FALLBACK_ENV_PATH;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.js (reported line 67)May include surrounding context.

js
const PRIMARY_ENV_PATH = path.join(os.homedir(), '.config', 'imap-smtp-email', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

// Find the .env file: primary location first, then fallback
function findEnvPath() {
  if (fs.existsSync(PRIMARY_ENV_PATH)) return PRIMARY_ENV_PATH;
  if (fs.existsSync(FALLBACK_ENV_PATH)) return FALLBACK_ENV_PATH;

Static analysis

No suspicious patterns detected.