Back to skill

Security audit

Simple Mail Client

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed email client, but it needs review because it can send, read, and modify email while also using risky dependency and transport settings.

Review before installing. Use only a dedicated mailbox or app-specific password, require TLS for SMTP and IMAP, restrict which recipients and folders the agent may use, regenerate the lockfile from an HTTPS registry, and update or audit the mail/YAML dependencies before trusting it with real mail.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
package-lock.json:22
Finding

Dependencies are locked to a third-party package mirror over plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: package-lock.json:22-25 and additional resolved entries throughout package-lock.json
Vulnerability Type: Insecure dependency source and software supply-chain exposure
Risk Level: Medium

Vulnerable Code

json
"node_modules/@pinojs/redact": {
  "version": "0.4.0",
  "resolved": "http://mirrors.tencentyun.com/npm/@pinojs/redact/-/redact-0.4.0.tgz",
  "integrity": "sha512-k2ENnmBugE/rzQfEcdWHcCY+/FM3VLzH9cYEsbdsoqrvzAKRhUZeRNhAZvB8OitQJ1TBed3yqWtdjzS6wJKBwg=="
}

The same plaintext mirror is used for security-sensitive runtime packages, including:

json
"node_modules/imapflow": {
  "version": "1.2.12",
  "resolved": "http://mirrors.tencentyun.com/npm/imapflow/-/imapflow-1.2.12.tgz",
  "integrity": "sha512-UX8qCKXZk2xExe/x8KPTSbhROdtUGP13bSLSjT9Sb3YwGuryD4aFNlGhbWBW5B1GtgHMRxVv9yvl61RqXgIQtQ=="
}
json
"node_modules/nodemailer": {
  "version": "6.10.1",
  "resolved": "http://mirrors.tencentyun.com/npm/nodemailer/-/nodemailer-6.10.1.tgz",
  "integrity": "sha512-Z+iLaBGVaSjbIzQ4pX6XV41HrooLsQ10ZWPUehGmuantvzWoDVBnmsdUcOIDM1t+yPor5pDhVlDESgOMEGxhHA=="
}

Technical Analysis

The lockfile directs npm to download dependencies from mirrors.tencentyun.com using unencrypted HTTP rather than HTTPS. This exposes dependency retrieval metadata and package responses to interception or modification by network-adjacent attackers.

npm integrity hashes provide an important mitigation: an attacker who only changes a package archive should normally cause installation to fail because its hash no longer matches the lockfile. Exploitation would therefore additionally require modification of the lockfile or integrity metadata, a compromised mirror serving an artifact matching already-poisoned metadata, an integrity-verification weakness, or a workflow that regenerates or accepts changed lockfiles without review.

The risk is significant becau ...[truncated 1317 chars]

Remediation
View remediation

Remediation Suggestions

  1. Regenerate package-lock.json using the official npm registry over HTTPS:
    bash
    npm config set registry https://registry.npmjs.org/
    rm -rf node_modules package-lock.json
    npm install
    
  2. Review and commit the regenerated lockfile, confirming that every resolved package URL uses HTTPS and an approved registry.
  3. Use npm ci in production and CI so installations cannot silently rewrite dependency versions.
  4. Require code review for all lockfile changes and fail CI when a resolved URL uses HTTP or an unapproved domain.
  5. Run dependency vulnerability and provenance checks, such as npm audit, software composition analysis, and package-signature or provenance verification where available.
  6. Pin reviewed dependency versions and periodically reassess transitive dependencies because these packages process credentials and untrusted email content.

T09 · Insecure Skill Coding Practices

Warning
Location
src/mailClient.ts:35
Finding

Mailbox credentials and email content may be transmitted without mandatory TLS

Content
View full analysis

Vulnerability Details

File Location: src/mailClient.ts:35-44 and src/mailClient.ts:73-82
Vulnerability Type: Optional transport encryption for password-authenticated SMTP and IMAP connections
Risk Level: Medium

Vulnerable Code

SMTP connection configuration:

ts
const transporter = nodemailer.createTransport({
  host: smtp.host,
  port: smtp.port,
  secure: smtp.useTLS,
  auth: {
    user: acc.auth.username,
    pass: acc.auth.password,
  },
});

IMAP connection configuration:

ts
const client = new ImapFlow({
  host: acc.imap.host,
  port: acc.imap.port,
  secure: acc.imap.useTLS,
  auth: {
    user: acc.auth.username,
    pass: acc.auth.password,
  },
});

The configuration schema explicitly permits TLS to be disabled:

ts
smtp: {
  host: string;
  port: number;
  useTLS: boolean;
};
auth: {
  username: string;
  password: string;
};

Technical Analysis

Both SMTP and IMAP authenticate with the configured username and password regardless of whether useTLS is enabled. If configuration sets useTLS: false, the client does not itself enforce an encrypted connection before supplying credentials.

For SMTP, secure: false can be appropriate when STARTTLS is required and successfully negotiated, but the code does not set requireTLS: true. It therefore lacks an application-level guarantee that authentication and message data will only be sent after encryption is established. For IMAP, disabling secure similarly permits a non-implicit-TLS connection without an explicit policy in this code requiring successful TLS upgrade before authentication.

Sending credentials to the operator-configured SMTP and IMAP hosts is necessary for the declared mail-client functionality and is not evidence of hidden exfiltration. The vulnerability is that confidentiality depends entirely on mutable configuration and server behavior rather than an ...[truncated 1430 chars]

Remediation
View remediation

Remediation Suggestions

  1. Reject SMTP and IMAP configurations that disable TLS unless a narrowly scoped, explicitly documented legacy override is enabled.
  2. For implicit TLS endpoints, require secure: true and standard secure ports such as SMTP 465 and IMAP 993.
  3. When SMTP STARTTLS is intentionally used, configure Nodemailer with requireTLS: true so delivery fails rather than authenticating over plaintext:
    ts
    const transporter = nodemailer.createTransport({
      host: smtp.host,
      port: smtp.port,
      secure: smtp.useTLS,
      requireTLS: !smtp.useTLS,
      auth: {
        user: acc.auth.username,
        pass: acc.auth.password,
      },
      tls: {
        rejectUnauthorized: true,
      },
    });
    
  4. Apply the equivalent mandatory-TLS policy to IMAP and fail closed if encryption or certificate validation cannot be established.
  5. Validate configuration at startup, including permitted port/TLS combinations and an allowlist of expected mail-server hostnames where operationally feasible.
  6. Keep certificate verification enabled and do not add permissive options such as rejectUnauthorized: false.
  7. Use dedicated mailbox accounts or app-specific passwords with the minimum mailbox permissions required.
  8. Store credentials in a secret manager or a configuration file with restrictive filesystem permissions rather than in a generally readable plaintext project file.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (21)

Known Vulnerable Dependency: nodemailer==8.0.1 — 10 advisory(ies): CVE-2026-82661 (Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary); GHSA-2x7j-588g-ccc2 (Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote den); GHSA-8m3c-c648-2xjj (Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disable) +7 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

The lockfile includes imapflow's bundled nodemailer 8.0.1, which static analysis reports as having multiple known advisories including header injection and denial-of-service issues. In a mail client skill, email parsing and header construction are core behaviors, so a vulnerable mail library is directly in the attack surface rather than incidental.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
84% confidence
Finding

The transitive ip-address 10.1.0 dependency has reported vulnerabilities involving parsing ambiguities and XSS in HTML-emitting methods. In this skill, it is pulled in through socks/imapflow, so exploitability depends on whether attacker-controlled IP strings or HTML output paths are reachable, but it still represents a real supply-chain risk in network-facing mail functionality.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

js-yaml 4.1.1 is flagged for multiple CPU exhaustion issues related to YAML parsing. If this skill loads YAML from untrusted or semi-trusted sources such as configuration, message content, or attachments, an attacker could trigger excessive CPU consumption and cause denial of service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nodemailer==6.10.1 — 12 advisory(ies): CVE-2026-82661 (Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary); GHSA-2x7j-588g-ccc2 (Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote den); GHSA-8m3c-c648-2xjj (Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disable) +9 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The top-level nodemailer 6.10.1 dependency is reported with multiple known vulnerabilities, including header injection and parsing-related denial of service. Because this is a generic mail client skill, nodemailer is likely used to construct or send attacker-influenced email content, making these issues especially relevant and increasing the likelihood of real exploitation impact.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

The resolved js-yaml version is reported with multiple advisories involving CPU-exhaustion and parser complexity issues. If this skill parses attacker-controlled or untrusted YAML, an adversary could trigger denial of service, which is especially relevant for a generic mail/client skill that may ingest external content or configuration.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nodemailer==6.10.1 — 12 advisory(ies): CVE-2026-82661 (Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary); GHSA-2x7j-588g-ccc2 (Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote den); GHSA-8m3c-c648-2xjj (Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disable) +9 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The resolved nodemailer version is flagged with numerous advisories, including CRLF/header injection and denial-of-service classes of issues. In a mail-sending skill, this context materially increases danger because the library is central to message construction and transport, so malformed user-controlled fields could potentially alter headers, bypass restrictions, or disrupt service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file exposes direct mail-sending and mailbox access handlers without any visible confirmation, authorization gating, or user-consent checks at the operation boundary. In an agent/tooling context, that means a prompt-injected or otherwise misdirected agent could send email, read messages, or change message state without the user explicitly approving the action, enabling unauthorized data access or external communication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code sends an email via SMTP at L047, which transmits user-provided recipients, subject, body, and attachments externally. There is no visible confirmation prompt, warning, or user-facing disclosure in this file before performing that outbound action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The code fetches full message content and metadata, including source data, from an email account at L145-L150. This is privacy-sensitive access to user communications, but the file contains no visible warning, prompt, or explanatory comment disclosing that message contents will be read.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code marks messages read/unread and can move them to another folder at L228-L235, which changes mailbox state and may be hard to undo. There is no visible confirmation prompt or warning in this file before these state-changing operations occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This method sends outbound email, including recipients, subject, body, and attachments, over SMTP via transporter.sendMail(...). The file contains no confirmation prompt, user-facing log/print, or explanatory comment/docstring warning that user content and attachments will be transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

This method connects to a mail account and fetches full message metadata and source content, which may include sensitive personal or business information. The code does not include a confirmation, user-visible logging, or explanatory comment/docstring disclosing that mailbox contents are being accessed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This method changes mailbox state by marking messages read/unread and moving messages between folders, which can affect user data organization and is not always easily reversible. The file provides no confirmation prompt, user-facing log, or explanatory documentation warning about these mailbox modifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code file defines a request/response interface for sending email, which is a safety-relevant network action that can transmit user data to external recipients. In this file there is no confirmation prompt, disclosure string, comment, or docstring warning users that the skill may send outbound messages and attachments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The dependency uses a caret range, which permits automatic installation of newer minor/patch versions that may introduce vulnerable or unreviewed code through the software supply chain. While common in JavaScript projects, this weakens build reproducibility and can expose the skill to unexpected dependency changes.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"build": "tsc -p ."
  },
  "dependencies": {
    "imapflow": "^1.0.0",
    "js-yaml": "^4.1.0",
    "nodemailer": "^6.9.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The caret range for js-yaml allows dependency resolution to newer releases without strict reproducibility, increasing supply-chain risk. In this file's context, the risk is elevated because js-yaml is also flagged as having known high-severity advisories in the resolved version stream.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
},
  "dependencies": {
    "imapflow": "^1.0.0",
    "js-yaml": "^4.1.0",
    "nodemailer": "^6.9.0"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Using a caret range for nodemailer permits non-deterministic dependency selection and increases exposure to supply-chain compromise or silently introduced vulnerable versions. This is more dangerous here because nodemailer is also identified as a known vulnerable dependency in the resolved version noted by static analysis.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"dependencies": {
    "imapflow": "^1.0.0",
    "js-yaml": "^4.1.0",
    "nodemailer": "^6.9.0"
  },
  "devDependencies": {
    "typescript": "^5.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 15)May include surrounding context.

json
"nodemailer": "^6.9.0"
  },
  "devDependencies": {
    "typescript": "^5.0.0",
    "@types/node": "^18.0.0",
    "@types/js-yaml": "^4.0.0",
    "@types/nodemailer": "^6.4.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
},
  "devDependencies": {
    "typescript": "^5.0.0",
    "@types/node": "^18.0.0",
    "@types/js-yaml": "^4.0.0",
    "@types/nodemailer": "^6.4.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"devDependencies": {
    "typescript": "^5.0.0",
    "@types/node": "^18.0.0",
    "@types/js-yaml": "^4.0.0",
    "@types/nodemailer": "^6.4.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"typescript": "^5.0.0",
    "@types/node": "^18.0.0",
    "@types/js-yaml": "^4.0.0",
    "@types/nodemailer": "^6.4.0"
  }
}

Static analysis

No suspicious patterns detected.