Back to skill

Security audit

SendGrid Skills

Security checks for vulnerabilities and agentic risk

Overview

This SendGrid skill is mostly coherent, but it can send real email through a configured SendGrid account and includes under-scoped safeguards around broad triggers and webhook testing.

Install only if you intend this agent to use your SendGrid account for live email operations. Use a SendGrid API key limited to Mail Send, keep it out of logs, confirm recipients and content before sending, avoid sensitive or regulated data unless authorized, and do not run the webhook verifier against untrusted or internal URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verify-inbound-setup.sh:45
Finding

Incomplete SSRF Protection in Webhook Endpoint Verification

Content
View full analysis
&1 || echo "000") ``` ### Technical Analysis The URL check validates only the URL's textual structure and HTTPS scheme. It does not resolve and classify the destination address before `curl` connects. Consequently, the expression accepts destinations such as: ```text https://127.0.0.1:8443/ https://internal-service.example/ https://service.internal/ ``` A publicly resolvable hostname can also resolve to a loopback, private, link-local, or otherwise reserved address. DNS rebinding may create a time-of-check/time-of-use discrepancy between validation and connection. Using HTTPS does not prevent SSRF. Internal services may use HTTPS with publicly trusted, locally trusted, or otherwise accepted certificates. The script therefore does not fulfill its comment that internal destinations are blocked. The request is a fixed multipart POST, and the response body is discarded. This limits the issue to blind SSRF with an HTTP-st ...[truncated 1417 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/send-test-email.sh:43
Finding

JSON Injection Through Unescaped Email Arguments

Content
View full analysis
$MESSAGE"} ] } EOF ) ``` ### Technical Analysis The recipient, sender, subject, and message values are inserted directly into a JSON here-document. No JSON encoder escapes quotation marks, backslashes, control characters, or newlines. Shell quoting of the initial variable assignments does not provide JSON encoding. A value containing a double quote can terminate its intended JSON string and introduce additional JSON syntax. Depending on the crafted input and SendGrid's duplicate-field and request validation behavior, this may alter fields in the authenticated API request. Less sophisticated input containing quotes or newlines can reliably produce malformed JSON and prevent delivery. This is not shell command injection: command substitutions embedded inside variable values are not reevaluated when the here-document expands them. The security issue is manipulation of the JSON data sent with the legitimate SendGrid API key. The companion `send-html-email.sh` avoids this issue by constructing its request with `jq --arg`, w ...[truncated 1480 chars]
Remediation
View remediation
" + $message + "")} ] }') ``` 2. Submit the encoded payload without further interpolation: ```bash curl \ --request POST \ --url https://api.sendgrid.com/v3/mail/send \ --header "Authorization: Bearer $SENDGRID_API_KEY" \ --header "Content-Type: application/json" \ --data "$JSON_PAYLOAD" ``` 3. Validate recipient and sender values with a suitable email-address parser before sending. 4. Enforce reasonable maximum lengths for addresses, subjects, and message bodies. 5. If converting plain text to HTML, HTML-escape the message before embedding it in markup. JSON encoding alone does not prevent HTML interpretation by email clients. 6. Keep the SendGrid API key restricted to Mail Send permissions and rotate it if misuse is suspected. 7. Add tests covering quotes, backslashes, tabs, carriage returns, newlines, Unicode, and attempted JSON structural injection. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader SendGrid integration covering both sending and receiving email, with routing to sub-skills for outbound transactional email and inbound webhook handling. The supplied code only implements inbound webhook payload parsing for SendGrid Inbound Parse data read from stdin. It does not send email, call the SendGrid API, receive webhooks over HTTP itself, or route to any sub-skills. While the inbound parsing portion is aligned with part of the description, the overall declared purpose materially overstates the implemented functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description portrays a multi-capability SendGrid integration covering both outbound and inbound email workflows and delegation to sub-skills. The actual code chunk only performs one narrow function: sending HTML email via SendGrid's v3 mail/send endpoint. It reads HTML from a string or validated .html/.htm file, builds JSON, and posts it to SendGrid. There is no code for receiving emails, webhook handling, parsing inbound requests, or dispatching to other sub-skills. This is a material scope mismatch because the description claims significant capabilities absent from the implementation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description claims a broader SendGrid platform integration covering both outbound sending and inbound email parsing/webhooks, with routing to sub-skills for those functions. The actual code only sends a test outbound email via the SendGrid API and checks for common error responses. It does not implement receiving emails, webhook handling, inbound parse logic, or any routing/orchestration behavior. While the code is related to one part of the declared domain (sending email via SendGrid), the declared purpose materially overstates the implemented behavior, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a general SendGrid email integration focused on sending transactional emails and receiving inbound emails through webhook routing. The supplied code does not send emails, receive/process inbound emails, or route to sub-skills. Its actual function is operational validation of SendGrid Inbound Parse configuration: it checks DNS MX records and optionally probes a webhook endpoint with a test POST. Those are related to SendGrid setup, but they are materially different capabilities from the declared purpose and represent infrastructure verification behavior that is not described.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/README.md (reported line 131)May include surrounding context.

md
* 
 * Usage:
 *   node parse-webhook-payload.js < payload.txt
 *   curl https://webhook.example.com/parse | node parse-webhook-payload.js
 * 
 * Reads multipart/form-data from stdin and outputs structured JSON
 */

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/README.md (reported line 227)May include surrounding context.

md
* 
 * Usage:
 *   node parse-webhook-payload.js < payload.txt
 *   curl https://webhook.example.com/parse | node parse-webhook-payload.js
 * 
 * Reads multipart/form-data from stdin and outputs structured JSON
 */

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/parse-webhook-payload.js (reported line 7)May include surrounding context.

js
* 
 * Usage:
 *   node parse-webhook-payload.js < payload.txt
 *   curl https://webhook.example.com/parse | node parse-webhook-payload.js
 * 
 * Reads multipart/form-data from stdin and outputs structured JSON
 */

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/parse-webhook-payload.js (reported line 133)May include surrounding context.

js
* 
 * Usage:
 *   node parse-webhook-payload.js < payload.txt
 *   curl https://webhook.example.com/parse | node parse-webhook-payload.js
 * 
 * Reads multipart/form-data from stdin and outputs structured JSON
 */

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This skill handles outbound email content and inbound parsed emails, including attachments, but the README does not warn about sensitive data exposure, attachment risks, or privacy/legal implications of processing email bodies. In an agent context, users may unknowingly cause collection, transmission, or storage of personal or confidential data, increasing the chance of unsafe deployment or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README gives the activation example "Send a welcome email to vince@example.com" as an AI-agent prompt without any narrowing constraints, exclusions, or trigger scoping. Because this is a common natural-language request, it could cause unintended invocation in broader assistant contexts where the user is merely discussing email content rather than explicitly invoking the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares shell-capable requirements and explicitly references executable scripts, but it does not define any tool scope such as permissions or allowed-tools. In an agent environment, that omission can enable broader-than-intended command execution or make review and enforcement of least privilege impossible.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like 'send email', 'receive email', and 'email webhook', which can cause the skill to activate in many generic email-related contexts. In an agent system, overly broad routing increases the chance of accidental invocation of shell/network-capable functionality and can expose sensitive environment-backed integrations such as SENDGRID_API_KEY to workflows that did not specifically require them.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/send-html-email.sh (reported line 136)May include surrounding context.

sh
}')

# Send via SendGrid API
RESPONSE=$(curl -s -w "\n%{http_code}" \
  --request POST \
  --url https://api.sendgrid.com/v3/mail/send \
  --header "Authorization: Bearer $SENDGRID_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/send-test-email.sh (reported line 56)May include surrounding context.

sh
echo ""

# Send email via SendGrid API
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST \
  https://api.sendgrid.com/v3/mail/send \
  -H "Authorization: Bearer $SENDGRID_API_KEY" \
  -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/send-html-email.sh (reported line 138)May include surrounding context.

sh
# Send email via SendGrid API
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST \
  https://api.sendgrid.com/v3/mail/send \
  -H "Authorization: Bearer $SENDGRID_API_KEY" \
  -H "Content-Type: application/json" \
  -d @- <<EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/send-test-email.sh (reported line 57)May include surrounding context.

sh
# Send email via SendGrid API
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST \
  https://api.sendgrid.com/v3/mail/send \
  -H "Authorization: Bearer $SENDGRID_API_KEY" \
  -H "Content-Type: application/json" \
  -d @- <<EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send-email/references/installation.md (reported line 75)May include surrounding context.

md
# Send email via SendGrid API
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST \
  https://api.sendgrid.com/v3/mail/send \
  -H "Authorization: Bearer $SENDGRID_API_KEY" \
  -H "Content-Type: application/json" \
  -d @- <<EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send-email/references/single-email-examples.md (reported line 88)May include surrounding context.

md
# Send email via SendGrid API
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST \
  https://api.sendgrid.com/v3/mail/send \
  -H "Authorization: Bearer $SENDGRID_API_KEY" \
  -H "Content-Type: application/json" \
  -d @- <<EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send-email/references/single-email-examples.md (reported line 97)May include surrounding context.

md
# Send email via SendGrid API
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST \
  https://api.sendgrid.com/v3/mail/send \
  -H "Authorization: Bearer $SENDGRID_API_KEY" \
  -H "Content-Type: application/json" \
  -d @- <<EOF

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script claims to prevent SSRF by validating the webhook URL, but its regex only checks for an HTTPS-shaped string and does not prevent requests to localhost, RFC1918/private IPs, link-local addresses, or internal-only hostnames. Because the script then issues a POST with curl to the supplied URL, a user can still make the machine running the script send requests to internal services, which is a real SSRF risk if this script is run in a trusted network or CI/admin environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and unconstrained, so this skill may activate for generic requests about sending email even when SendGrid is not intended. In an agent setting, over-broad routing can cause inappropriate use of an external email service, increasing the chance of accidental data disclosure or unintended message sending.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages sending recipient addresses, message contents, personalization data, and attachments to SendGrid without any privacy or sensitivity warning. Users or downstream agents may send confidential, regulated, or unnecessary personal data to a third-party provider without informed consent or minimization.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send-email/references/installation.md (reported line 72)May include surrounding context.

dotnet add package SendGrid

text

## cURL

```bash
curl -X POST "https://api.sendgrid.com/v3/mail/send" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes a cURL example that performs a real POST request to SendGrid's mail send endpoint and includes recipient, sender, subject, and content data. The surrounding documentation does not warn users that running the example will send email and disclose message data to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file provides ready-to-run examples that transmit message content, recipient addresses, and attachments to SendGrid, and it references the SENDGRID_API_KEY credential. The description contains no warning about sending data to a third-party service, using live recipients, or handling API keys, which fits the markdown-specific missing-warning criterion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.