Back to skill

Security audit

IMAP SMTP Email

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real IMAP/SMTP email skill, but it handles full mailbox access, outbound email, local files, and stored credentials in ways users should review carefully before installing.

Install only if you are comfortable giving the skill mailbox read access and the ability to send mail as you. Prefer app-specific passwords, keep .env private and out of backups/repos, restrict ALLOWED_READ_DIRS and ALLOWED_WRITE_DIRS tightly, review recipients and attachments before sending, and avoid using directories where untrusted local users or processes can create symlinks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/imap.js:16
Finding

Symbolic-Link Bypass of the Attachment Write Allowlist

Content
View full analysis
path.resolve(d.trim().replace(/^~/, os.homedir())) ); const allowed = allowedDirs.some(dir => resolved === dir || resolved.startsWith(dir + path.sep) ); if (!allowed) { throw new Error(`Access denied: '${dirPath}' is outside allowed write directories`); } return resolved; } ``` The validated path is subsequently used to write attachment data: ```javascript const resolvedDir = validateWritePath(outputDir); if (!fs.existsSync(resolvedDir)) { fs.mkdirSync(resolvedDir, { recursive: true }); } const downloaded = []; for (const attachment of parsed.attachments) { if (specificFilename && attachment.filename !== specificFilename) { continue; } if (attachment.content) { const filePath = path.join(resolvedDir, sanitizeFilename(attachment.filename)); fs.writeFileSync(filePath, attachment.content); ``` ### Technical Analysis The write allowlist compares lexically normalized paths produced by `path.resolve()`. This removes relative components but does not resolve symbolic links or establish that the final filesystem destination remains beneath a canonical allowed root. Consequently, an allowed directory, one of its descendants, or an existing destination file can be a symbolic link to a location outside `ALLOWED_WRITE_DIRS`. `fs.writeFileSync()` follows symbolic links by default. Filename sanitization prevents direct `../` traversal in attachment names, but i ...[truncated 1471 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/smtp.js:15
Finding

TOCTOU Symbolic-Link Bypass of the File Read Allowlist

Content
View full analysis
path.resolve(d.trim().replace(/^~/, os.homedir())) ); const allowed = allowedDirs.some(dir => realPath === dir || realPath.startsWith(dir + path.sep) ); if (!allowed) { throw new Error(`Access denied: '${inputPath}' is outside allowed read directories`); } return realPath; } ``` For attachments, the validated canonical path is discarded and the original pathname is passed to Nodemailer: ```javascript function readAttachment(filePath) { validateReadPath(filePath); if (!fs.existsSync(filePath)) { throw new Error(`Attachment file not found: ${filePath}`); } return { filename: path.basename(filePath), path: path.resolve(filePath), }; } ``` The same validation-then-reopen pattern is used for message content: ```javascript if (options['subject-file']) { validateReadPath(options['subject-file']); options.subject = fs.readFileSync(options['subject-file'], 'utf8').trim(); } if (options['body-file']) { validateReadPath(options['body-file']); const content = fs.readFileSync(options['body-file'], 'utf8'); if (options['body-file'].endsWith('.html') || options.html) { options.html = content; } else { options.text = content; } } else if (options['html-file']) { validateReadPath(options['html-file']); options.html = fs.readFileSync(options['html-fi ...[truncated 2078 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package.json:13
Finding

Non-Reproducible Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code substantially matches the read/search/fetch/mark/list/download-attachment portions of the description. However, the declared purpose explicitly includes 'send email via IMAP/SMTP' and 'send emails with attachments,' while the supplied code contains no SMTP logic, no outbound mail construction, and no send command. Instead, it is an IMAP CLI focused on reading messages and downloading attachments locally. Attachment downloading is an extra read-related detail that is adjacent to the declared scope, not a separate unrelated capability. The main material mismatch is that outbound email functionality is declared but absent from the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear description/behavior mismatch. The declared purpose presents a combined IMAP/SMTP email tool with substantial mailbox-management features. The actual code chunk is an SMTP CLI only: it creates a Nodemailer transporter, verifies SMTP connectivity, sends emails, optionally attaches files, and reads local files for message subject/body/attachments subject to allowed-directory restrictions. There is no code for connecting to IMAP servers, listing or searching messages, reading inbox contents, or changing read/unread state. While sending email with attachments is consistent with part of the description, the major claimed read-side functionality is absent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
node scripts/imap.js check [--limit 10] [--mailbox INBOX] [--recent 2h]

Credential Access

High
Category
Privilege Escalation
Confidence
75% confidence
Finding

The script automatically loads secrets from a local ../.env file, which creates a credential exposure risk if that file is broadly readable, accidentally committed, or reused across skills. In an agent-skill context, implicit secret loading expands the trust boundary because simply invoking the script can access mailbox credentials without an explicit runtime secret handoff.

Content

Scanner excerpt · scripts/imap.js (reported line 14)May include surrounding context.

js
const path = require('path');
const fs = require('fs');
const os = require('os');
require('dotenv').config({ path: path.resolve(__dirname, '../.env') });

function validateWritePath(dirPath) {
  const allowedDirsStr = process.env.ALLOWED_WRITE_DIRS;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/smtp.js (reported line 13)May include surrounding context.

js
const path = require('path');
const os = require('os');
const fs = require('fs');
require('dotenv').config({ path: path.resolve(__dirname, '../.env') });

function validateReadPath(inputPath) {
  let realPath;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/smtp.js (reported line 81)May include surrounding context.

js
const path = require('path');
const os = require('os');
const fs = require('fs');
require('dotenv').config({ path: path.resolve(__dirname, '../.env') });

function validateReadPath(inputPath) {
  let realPath;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 9)May include surrounding context.

sh
echo "  IMAP/SMTP Email Skill Setup"
echo "================================"
echo ""
echo "This script will help you create a .env file with your email credentials."
echo ""

# Prompt for email provider

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 169)May include surrounding context.

sh
echo "  IMAP/SMTP Email Skill Setup"
echo "================================"
echo ""
echo "This script will help you create a .env file with your email credentials."
echo ""

# Prompt for email provider

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 170)May include surrounding context.

sh
echo "  IMAP/SMTP Email Skill Setup"
echo "================================"
echo ""
echo "This script will help you create a .env file with your email credentials."
echo ""

# Prompt for email provider

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 171)May include surrounding context.

sh
echo "  IMAP/SMTP Email Skill Setup"
echo "================================"
echo ""
echo "This script will help you create a .env file with your email credentials."
echo ""

# Prompt for email provider

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Beginning at this line, the script writes IMAP and SMTP usernames and passwords into a plaintext .env file. Because this skill is specifically for email access, compromise of these credentials could expose mailbox contents, attachments, contacts, and enable unauthorized sending as the user.

Content

Scanner excerpt · setup.sh (reported line 143)May include surrounding context.

sh
read -p "Allowed directories for reading files (comma-separated, e.g. ~/Downloads,~/Documents): " ALLOWED_READ_DIRS
read -p "Allowed directories for saving attachments (comma-separated, e.g. ~/Downloads): " ALLOWED_WRITE_DIRS

# Create .env file
cat > .env << EOF
# IMAP Configuration
IMAP_HOST=$IMAP_HOST

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This finding is part of the same credential-persistence behavior: the generated .env file contains sensitive mail authentication data in plaintext. In the context of an email skill, these credentials grant access to highly sensitive communications and can be reused for mailbox reading and message transmission.

Content

Scanner excerpt · setup.sh (reported line 144)May include surrounding context.

sh
read -p "Allowed directories for saving attachments (comma-separated, e.g. ~/Downloads): " ALLOWED_WRITE_DIRS

# Create .env file
cat > .env << EOF
# IMAP Configuration
IMAP_HOST=$IMAP_HOST
IMAP_PORT=$IMAP_PORT

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares access to environment secrets and relies on shell and network-capable commands, but does not define any explicit tool scope or permission boundaries. In an agent ecosystem, that omission increases the chance the skill can be invoked with broader-than-necessary capabilities, including use of email credentials and outbound network access without clear user-facing constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill supports outbound email with optional body-file, html-file, and attachment inputs, but the description and security notes do not clearly warn that local file content and user data may be transmitted to external recipients. In an agent setting, this can lead to unintended exfiltration of sensitive information if a user or upstream workflow passes the wrong file or recipient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code creates directories and writes email attachment contents to the local filesystem, which is a safety-relevant operation affecting user data and system state. While the path is validated, there is no confirmation prompt or user-facing disclosure at the point of write, and the nearby comments are implementation notes rather than warnings to the user.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The test command is labeled and documented as a connection test, but it actually sends a real email to the configured account. In agent or automation contexts, this can cause unintended outbound actions, spam/noise, and policy violations because a supposedly non-destructive check performs a side effect on an external system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes the supplied email password/app password into a plaintext .env file on disk, and although it later applies mode 600, it does not clearly warn the user before persisting secrets locally. Storing long-lived mail credentials on disk increases exposure through backups, shell working-directory mistakes, malware, accidental commits, or other local compromise.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 170)May include surrounding context.

sh
echo ""
echo "✅ Created .env file"
chmod 600 .env
echo "✅ Set .env file permissions to 600 (owner read/write only)"
echo ""
echo "Testing connections..."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup script automatically attempts to send a real email after collecting credentials, without asking for a just-in-time confirmation immediately before transmission. This can cause unintended outbound communication, trigger provider alerts, or violate user expectations in environments where sending mail has compliance or operational consequences.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/imap.js:17