Back to skill

Security audit

ai-agent-email-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says for email, but it gives an agent powerful mail-account controls with too few built-in safeguards.

Install only if you intend to let an agent operate the configured mailbox, including sending mail and deleting messages or folders. Use a dedicated account, app password, or narrowly scoped OAuth grant where possible; keep TLS and certificate verification enabled; use only trusted OAuth token endpoints; and require human review before sends, forwards, deletes, expunges, and folder deletion.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common/auth.py:50
Finding

OAuth Credentials Can Be Transmitted to an Arbitrary or Insecure Token Endpoint

Content
View full analysis
dict[str, Any]: """Read OAuth2 config from environment variables.""" result = oauth_cfg.copy() if oauth_cfg else {} result["client_id"] = os.environ.get("EMAIL_OAUTH2_CLIENT_ID", oauth_cfg.get("client_id", "") if oauth_cfg else "") result["client_secret"] = os.environ.get("EMAIL_OAUTH2_CLIENT_SECRET", oauth_cfg.get("client_secret", "") if oauth_cfg else "") result["refresh_token"] = os.environ.get("EMAIL_OAUTH2_REFRESH_TOKEN", oauth_cfg.get("refresh_token", "") if oauth_cfg else "") result["token_url"] = os.environ.get("EMAIL_OAUTH2_TOKEN_URL", oauth_cfg.get("token_url", "") if oauth_cfg else "") r ...[truncated 2322 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common/imap_utils.py:20
Finding

IMAP and SMTP Authentication Can Proceed Without Secure Transport or Certificate Verification

Content
View full analysis
imaplib.IMAP4_SSL | imaplib.IMAP4: imap_cfg = account_cfg["imap"] host = imap_cfg.get("host") port = imap_cfg.get("port") tls = bool(imap_cfg.get("tls", True)) starttls = bool(imap_cfg.get("starttls", False)) timeout = imap_cfg.get("timeout", account_cfg.get("timeout", 30)) ssl_verify = account_cfg.get("ssl_verify", True) ssl_ca_path = account_cfg.get("ssl_ca_path") try: # Create SSL context ssl_context = ssl.create_default_context() if not ssl_verify: ssl_context.check_hostname = False ssl_context.verify_mode = ssl.CERT_NONE if ssl_ca_path: ssl_context.load_verify_locations(ssl_ca_path) # Connect if tls: client: imaplib.IMAP4_SSL | imaplib.IMAP4 = imaplib.IMAP4_SSL( host, int(port), timeout=int(timeout), ssl_context=ssl_context ) else: client = imaplib.IMAP4(host, int(port), timeout=int(timeout)) if starttls: client.starttls(ssl_context) # Authenticate auth_type = _detect_auth_type() if auth_type == "oauth2": email = account_cfg.get("email") oauth_cfg = _get_oauth2_from_env({}) access_token = get_oauth2_token(oauth_cfg) auth_string = f"user={email}\1auth=Bearer {access_token}\1\1" auth_bytes = auth_string.encode("utf-8") status, detail = client.authenticate("XOAUTH2", lambda x=None: auth_bytes) else: ...[truncated 5061 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common/auth.py (reported line 49)May include surrounding context.

python
def get_oauth2_token(oauth_cfg: dict[str, Any]) -> str:
    """Fetches a new OAuth2 access token using the refresh token with retry logic."""
    token_url = oauth_cfg.get("token_url")
    refresh_token = oauth_cfg.get("refresh_token")
    client_id = oauth_cfg.get("client_id")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes sensitive capabilities via environment variables and networked email operations, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This weakens policy enforcement and reviewability, increasing the chance an agent can access credentials or perform external email actions without clear operator awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents destructive actions such as deleting messages and deleting mailboxes without prominent warnings about permanence, expunge behavior, or recovery limitations. In an autonomous-agent context, unclear safeguards can lead to irreversible loss of email data or folders through routine prompting mistakes or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill enables sending, replying to, and forwarding emails, including attachments, but does not prominently warn that message content and files are transmitted to external recipients and mail infrastructure. In an agent setting this can cause accidental disclosure of sensitive data, prompt-derived secrets, or private mailbox content.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 309)May include surrounding context.

md
Mark email(s) with flags.

| Request fields |                                                                                    |
| -------------- | ---------------------------------------------------------------------------------- |
| `uids`         | string[] or comma-separated string, required                                       |
| `markType`     | `read`, `unread`, `flag`, `unflag`, `spam`, `notspam`, `junk`, `notjunk`, required |

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 529)May include surrounding context.

md
### Security Warnings

⚠️ **SSL Verification**: Setting `ssl_verify = false` in config disables certificate validation and exposes connections to man-in-the-middle attacks. Only disable for local development/testing.

⚠️ **IMAP Injection Protection**: User-provided search queries are validated against a whitelist of safe commands. Custom queries containing `()";` characters will be rejected.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 529)May include surrounding context.

md
### Security Warnings

⚠️ **SSL Verification**: Setting `ssl_verify = false` in config disables certificate validation and exposes connections to man-in-the-middle attacks. Only disable for local development/testing.

⚠️ **IMAP Injection Protection**: User-provided search queries are validated against a whitelist of safe commands. Custom queries containing `()";` characters will be rejected.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This function permanently expunges messages by UID, which is a destructive and generally irreversible mail operation. Although the code checks for UIDPLUS support and reports failures, it provides no confirmation prompt, explicit warning comment/docstring, or user-facing disclosure that the action will permanently remove mail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code issues an IMAP delete operation on the specified mailbox, which is a destructive and potentially irreversible action. There is no visible confirmation prompt, user-facing disclosure, or explanatory comment/docstring in this file warning that the folder will be deleted.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes mailbox management, reading/searching, sending/replying/forwarding, and attachment management, but does not mention deleting email. This file marks messages with the IMAP \Deleted flag and can permanently expunge them, which is a materially destructive mail operation beyond the listed description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code performs destructive deletion and optional expunge solely based on request parameters, with no in-file confirmation, safeguard, or friction before permanently removing messages. In an agentic context, a mistaken prompt interpretation, compromised upstream tool call, or unsafe automation path could cause irreversible loss of user email.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs irreversible message movement, including COPY/STORE +FLAGS (\Deleted) and expunge fallback behavior, but the file contains no confirmation prompt, user-visible logging, or explanatory docstring/comment warning about the destructive effect. Moving or expunging mail can affect user data integrity, so the operation should be clearly disclosed somewhere in the skill implementation or documentation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The read handler performs a state-changing IMAP STORE operation that adds the \Seen flag as part of what appears to be a content-retrieval workflow. In an agentic email skill, silently mutating message state during a read can mislead users, alter downstream automation, and allow an agent or prompt-injected workflow to hide unread mail simply by accessing it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Reading an email silently marks it as read with no caller-visible warning or confirmation logic in this file. In the context of a scriptable agent email skill, this is more dangerous because untrusted prompts, automated triage, or background inspection can unintentionally change mailbox state and conceal unread messages from the human user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This handler sends an email immediately via SMTP based solely on the request payload and the fetched original message, with no approval, confirmation, policy check, or recipient safety control in this file. In an agent skill that enables programmatic mailbox actions, that creates a real risk of unintended or adversary-prompted outbound mail, including reply-all propagation, attachment exfiltration, or social-engineering messages sent from the user's account.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes script-based email operations such as mailbox management, reading, searching, and sending mail, but this config module also depends on environment-based credential discovery via _detect_auth_type(). While email access requires authentication, reading process environment variables is a separate sensitive capability that is not mentioned in the stated purpose for this skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The comment frames marking as read as occurring only after content is parsed, suggesting the state change is a deliberate post-parse step. However, the code has already fetched the full message body at L063-L079, so the comment does not accurately describe the effective behavior boundary and can mislead reviewers about when side effects occur relative to mail access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.