T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
Hardcoded Live SMTP Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This email skill is transparent about what it does, but it embeds live SMTP credentials and enables arbitrary outbound email without enough guardrails.
Review this skill carefully before installing. Only use it if you intentionally want this agent to send email through the documented yeah.net account, and rotate/remove the embedded SMTP password first if the skill will be shared, logged, or stored anywhere outside a trusted private workspace.
SKILL.md:28Hardcoded Live SMTP Credentials
The skill explicitly instructs an agent to create and run a script that transmits data to an external SMTP service using embedded live credentials, but it does not provide a meaningful safety warning, consent check, or data-handling restriction for outbound transmission. In an agent setting, this makes exfiltration and unauthorized external communication easier because arbitrary recipient, subject, and body content can be sent off-host with a one-shot command.
No suspicious patterns detected.