Back to skill

Security audit

inbox-zero-warrior

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local email-export triage helper with no evidence of hidden execution, exfiltration, or destructive automation.

Install only if you are comfortable processing local email exports. Review generated delete, file, reply, and unsubscribe recommendations manually, and treat every unsubscribe URL as untrusted unless you verify the sender and destination yourself.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/newsletter_detector.py:124
Finding

Untrusted unsubscribe URLs are presented as safe one-click actions

Content
View full analysis
]+)>', list_unsub) http_match = re.search(r'<(https?://[^>]+)>', list_unsub) if http_match: unsub_info['method'] = 'link' unsub_info['link'] = http_match.group(1) elif mailto_match: unsub_info['method'] = 'email' unsub_info['email'] = mailto_match.group(1) ``` The extracted value is subsequently presented as an easy one-click action: ```python if easy: unsub = sender_info['unsubscribe'] if unsub['method'] == 'link': lines.append(f" Link: {unsub['link']}") elif unsub['method'] == 'email': lines.append(f" Email: {unsub['email']}") ``` ### Technical Analysis The `List-Unsubscribe` header and email body are controlled by the email sender. The implementation accepts any string matching an HTTP or HTTPS URL and propagates it into a prioritized unsubscribe report without validating: - The destination hostname or resolved IP address - Localhost, private, link-local, loopback, or reserved network ranges - Cloud metadata service addresses - Embedded credentials - Non-default ports - URL normalization or parser ambiguities - Redirect destinations - Whether the unsubscribe destination is associated with the sender's domain The report labels any successfully extracted method as an easy unsubscribe action and displays a success indicator. This creates an unsafe trust signal around attacker-controlled content. The current script only prints the URL and does not itself issue a network request. Exploitation therefore requires a user or downstream automation to follow the generated ...[truncated 2158 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code substantially supports the triage/classification aspect of the description: it classifies urgency, category, and recommended action; detects newsletters; creates a summary report; and shows urgent items. However, several declared capabilities are not implemented. There is no functionality to draft or generate quick replies—only heuristic detection that an email may need a response. There is also no bulk unsubscribe action, only classification of newsletters with a recommended 'unsubscribe' label. Finally, while it can generate an on-demand report, it does not produce daily digests or include any scheduling/recurring behavior. Because these are prominent parts of the declared purpose, the description overstates the implemented functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broader inbox assistant with multiple major capabilities: urgency classification, quick reply generation, newsletter detection/unsubscribe, and daily digests. The supplied code implements only the newsletter detection/unsubscribe subset. It parses email JSON, detects newsletters via List-Unsubscribe headers, ESP domains, body/subject heuristics, extracts unsubscribe links or mailto addresses, groups newsletters by sender, and produces a prioritized unsubscribe list. There is no logic for triaging urgency, categorizing general emails, composing replies, or generating daily digests. This is a material description-to-behavior mismatch because the implemented primary purpose is narrower and different from the full declared skill behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broader inbox-zero assistant with multiple capabilities: triage/categorization, reply generation, newsletter detection/unsubscribe, and daily digests. The supplied code chunk only covers one subset of that description: generating suggested email replies from canned templates. It reads an already-triaged JSON input and filters emails based on existing action labels, but it does not itself classify urgency, detect newsletters, unsubscribe from anything, or create digests. Therefore the description materially overstates the behavior of this code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README encourages users to export and process entire inbox datasets, classify messages, and generate unsubscribe/delete actions without warning that email exports commonly contain sensitive personal, financial, and business information. Even though this is documentation rather than executable code, normalizing bulk handling of mailbox contents without privacy, retention, or review guidance increases the risk of inadvertent data exposure, unsafe automation, or destructive actions on important messages.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises operational behaviors that can plausibly require modifying files or generated outputs, but it declares no tool scope or permission boundaries. Missing explicit tool restrictions increases the risk that an agent runtime grants broader-than-necessary file-write access, enabling unintended local file modification or unsafe persistence of sensitive email-derived data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill processes exported email contents, which commonly include sensitive personal, financial, and business data, yet it provides no explicit privacy or data-handling warning. This increases the chance users expose confidential mailbox exports to systems, storage locations, or downstream processing they would not have chosen if the privacy implications were made clear.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow encourages bulk unsubscribe actions without an explicit requirement for user review or warning about account-impacting consequences. Automated or poorly reviewed unsubscribes can remove users from important communications, confirm active addresses to senders, or trigger irreversible preference changes across many messages at once.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes capabilities to generate quick replies and produce daily digests, but this file implements urgency/category/action classification plus a simple report. No code creates reply drafts or composes a digest artifact beyond aggregate counts, so the implemented behavior is materially narrower than the stated skill behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The top-level docstring frames the script as an 'Email Triage Classifier' that 'Processes email exports in JSON format,' but the CLI also supports report and urgent commands that operate on triaged JSON rather than raw exports. This is a documentation-to-code divergence about the script's actual operational scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.