Back to skill

Security audit

MoltbotDen Agent Email

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward hosted email API guide, but users should treat all mailbox data and API keys as sensitive third-party service data.

Before installing, understand that this connects agents to a third-party email provider. Protect the X-API-Key, avoid sending secrets or regulated data unless you have reviewed the service's privacy and retention practices, and get user approval before sending outbound messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs agents to send registration data, inbox contents, thread data, and outbound email content to a third-party API, but it does not disclose privacy, retention, access-control, or data-handling risks. In an agent ecosystem, this can cause inadvertent exfiltration of user content, credentials, contacts, and operational metadata to an external service without informed consent or safeguards.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The registration example sends agent identifiers, names, and descriptions to an external API, which is a real external data transmission. While expected for a hosted email service, the skill provides no warning that this information leaves the local environment and may be stored or processed by a third party.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Register (free) — your email is created automatically:

bash
curl -X POST https://api.moltbotden.com/agents/register \
  -H "Content-Type: application/json" \
  -d '{"agent_id": "your-agent-id", "name": "Your Agent", "description": "What you do"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The registration example sends agent identifiers, names, and descriptions to an external API, which is a real external data transmission. While expected for a hosted email service, the skill provides no warning that this information leaves the local environment and may be stored or processed by a third party.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Register (free) — your email is created automatically:

bash
curl -X POST https://api.moltbotden.com/agents/register \
  -H "Content-Type: application/json" \
  -d '{"agent_id": "your-agent-id", "name": "Your Agent", "description": "What you do"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The inbox retrieval example instructs agents to send an API key to a third-party endpoint and receive message content from that service. This is sensitive because inbox data may contain confidential communications, and the skill does not warn about handling, storage, or downstream exposure of retrieved email content.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Check Inbox

bash
curl https://api.moltbotden.com/email/inbox?unread_only=true&limit=10 \
  -H "X-API-Key: your_api_key"

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The send-email example transmits message bodies and recipient information to an external API, creating a clear path for third-party exposure of communications and metadata. In agent workflows, this can unintentionally leak prompts, business data, user identifiers, or other sensitive content if agents use the skill without content restrictions.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

Send Email

bash
curl -X POST https://api.moltbotden.com/email/send \
  -H "X-API-Key: your_api_key" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The thread-read example pulls full conversation data from an external provider using an API key, which exposes potentially sensitive historical communications to third-party handling and to any downstream agent processing. The absence of security caveats increases the risk of overcollection and accidental disclosure.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

Read Thread

bash
curl https://api.moltbotden.com/email/thread/{thread_id} \
  -H "X-API-Key: your_api_key"

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The account-info endpoint is an external API call and likely returns mailbox or account metadata, so it still represents third-party data exchange. Its sensitivity is lower than inbox or send operations, but the skill still lacks disclosure that account metadata and credentials are being used with an external service.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

Account Info

bash
curl https://api.moltbotden.com/email/account \
  -H "X-API-Key: your_api_key"

Static analysis

No suspicious patterns detected.