Back to skill

Security audit

Fastmail

Security checks for vulnerabilities and agentic risk

Overview

This Fastmail skill does what it claims, but it handles very sensitive email and calendar actions with weak safeguards and insecure setup guidance.

Review this carefully before installing. Use a dedicated, narrowly scoped Fastmail token and app password if possible, avoid storing them in shell profiles or committed .env files, do not run the curl-to-bash installer blindly, and require explicit review before any send, reply-all, delete, bulk delete, calendar deletion, or invitation response action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:246
Finding

Remote installer is downloaded and executed without verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/jmap-client.ts:28
Finding

Fastmail bearer token can be forwarded to an unvalidated session-provided URL

Content
View full analysis
{ if (this.session) return this.session; const response = await fetch('https://api.fastmail.com/jmap/session', { headers: { 'Authorization': `Bearer ${this.token}`, }, }); if (!response.ok) { throw new Error(`Failed to get session: ${response.statusText}`); } this.session = await response.json(); return this.session!; } async call(methodCalls: [string, Record, string][]): Promise { const session = await this.getSession(); const request: JMAPRequest = { using: [ 'urn:ietf:params:jmap:core', 'urn:ietf:params:jmap:mail', 'urn:ietf:params:jmap:submission', ], methodCalls, }; const response = await fetch(session.apiUrl, { method: 'POST', headers: { 'Content-Type': 'application/json', 'Authorization': `Bearer ${this.token}`, }, body: JSON.stringify(request), }); if (!response.ok) { throw new Error(`JMAP call failed: ${response.statusText}`); } return response.json(); } ``` ### Technical Analysis The client obtains `apiUrl` from the JMAP session response and subsequently sends the Fastmail bearer token to that URL. It does not verify that the URL uses HTTPS or belongs to an approved Fastmail origin. JMAP session discovery legitimately returns service URLs, so using a session-provided endpoint is necessary. However, this Fastmail-specific Skill should validate that the discovered destination remains within its intended trust boundary before attaching a full-account credential. The absence of validation creates a credential-forwarding primitive if the session response becomes attacker-controlled. ### Attack Path 1. An attacker gains the ability to alter the JMAP ...[truncated 858 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tools/calendar.ts:263
Finding

Unescaped user input permits iCalendar property injection

Content
View full analysis
0) { for (const attendee of event.attendees) { const attendeeStr = attendee.name ? `CN="${attendee.name}":mailto:${attendee.email}` : `mailto:${attendee.email}`; icsData += `ATTENDEE;${attendeeStr}\n`; } } ``` ### Technical Analysis Calendar titles, descriptions, locations, reminder descriptions, attendee names, and attendee email addresses are interpolated directly into RFC 5545 iCalendar records. The implementation neither escapes iCalendar text and parameter delimiters nor rejects carriage-return and newline characters. An input containing a newline can terminate the intended property and introduce new properties or component boundaries. Special characters in attendee parameters can similarly alter the syntax of an `ATTENDEE` property. A maintained serializer would distinguish TEXT escaping from parameter-value escaping, but this implementation treats both as raw strings. This is especially relevant to an Agent Skill because untrusted content from an email, website, or user-supplied document may be copied into calendar fields automatically. ### Attack Pa ...[truncated 1090 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:65
Finding

Documentation encourages plaintext persistence of long-lived Fastmail credentials

Content
View full analysis
> .env echo "FASTMAIL_USERNAME=your-email@fastmail.com" >> .env echo "FASTMAIL_PASSWORD=your-app-password-here" >> .env ``` ```bash source ~/.zshrc # or source ~/.bashrc ``` ### Technical Analysis The setup instructions encourage users to store Fastmail API tokens and app passwords as plaintext in shell initialization files or a project-local `.env` file. No restrictive permissions, ignore rules, secret-manager integration, or shell-history precautions are specified. Placing literal credentials in `echo` commands can preserve them in command history. A project-local `.env` file can be copied into backups, support archives, container contexts, or source-control commits. Shell profiles may also expose the credentials to every process launched from the user's interactive shell, exceeding the minimum runtime scope required by this Skill. The CLI code shown in the audit reads `process.env` directly and does not itself load `.env`, making the documented `.env` option incomplete unless another launcher loads it. ### Attack Path 1. A user follows the documented setup instructions. 2. Credentials are written into a shell profile, `.env` file, and potentially shell history. 3. Another local process, user, backup system, development tool, or accidental repository commit captures the plaintext data. 4. An attacker retrieves the token or app password. 5. The attacker authenticates to Fastmail APIs within the credential's permissions. ### Impact Assess ...[truncated 350 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:10
Finding

Unpinned dependency resolution is performed without a committed lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
Findings (91)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The README instructs users to place a full-access Fastmail API token into a local .env file. While common in development, this increases the risk of credential exposure through accidental commits, backups, local file disclosure, or unsafe sharing, especially because the token grants broad mailbox access.

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

Or create a .env file:

bash
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env
echo "FASTMAIL_USERNAME=your-email@fastmail.com" >> .env
echo "FASTMAIL_PASSWORD=your-app-password-here" >> .env

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The README instructs storing the Fastmail username in .env alongside other credentials. By itself the username is less sensitive, but colocating account identifiers with secrets in a plaintext file increases the usefulness of any file disclosure or accidental repository leak.

Content

Scanner excerpt · README.md (reported line 80)May include surrounding context.

bash
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env
echo "FASTMAIL_USERNAME=your-email@fastmail.com" >> .env
echo "FASTMAIL_PASSWORD=your-app-password-here" >> .env

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The README instructs users to store a Fastmail app password in a plaintext .env file. This is sensitive credential material that can enable unauthorized calendar access if the file is exposed via source control, endpoint compromise, shell tooling, or logs; the skill context makes this more dangerous because the account may contain private scheduling and relationship data.

Content

Scanner excerpt · README.md (reported line 81)May include surrounding context.

bash
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env
echo "FASTMAIL_USERNAME=your-email@fastmail.com" >> .env
echo "FASTMAIL_PASSWORD=your-app-password-here" >> .env

Then reload:

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The README recommends installing Bun with curl ... | bash, which executes a remotely fetched script without prior verification. If the transport endpoint, CDN, DNS, or upstream distribution is compromised, users could run attacker-controlled code directly on their system.

Content

Scanner excerpt · README.md (reported line 246)May include surrounding context.

md
### Requirements

- [Bun](https://bun.sh/) - JavaScript runtime (install with `curl -fsSL https://bun.sh/install | bash`)

## Troubleshooting

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This second mismatch finding indicates the skill claims email, reminders, RSVP handling, and timezone auto-detection, while the observed implementation lacks those features and may rely on undeclared authentication behavior. Such overclaiming can mislead users into supplying API tokens, usernames, and passwords to a tool whose real behavior is insufficiently disclosed, increasing the risk of credential misuse or unsafe execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This second mismatch finding indicates the skill claims email, reminders, RSVP handling, and timezone auto-detection, while the observed implementation lacks those features and may rely on undeclared authentication behavior. Such overclaiming can mislead users into supplying API tokens, usernames, and passwords to a tool whose real behavior is insufficiently disclosed, increasing the risk of credential misuse or unsafe execution.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/cli.js (reported line 1589)May include surrounding context.

js
+value, offset = offset >>> 0, !noAssert)
    checkIEEE754(buf, value, offset, 4, 340282346638528860000000000000000000000, -340282346638528860000000000000000000000);
  return write(buf, value, offset, littleEndian, 23, 4), offset + 4;
}
function writeDouble(buf, value, offset, littleEndian, noAssert) {
  if (value = +value, offset = offset >>> 0, !noAssert)
    checkIEEE754(buf, value, offset, 8, 179769313486231570000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000, -179769313486231570000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

Unvalidated Output Injection

High
Category
Output Handling
Confidence
100% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · dist/cli.js (reported line 9573)May include surrounding context.

js
ok: davResponse.ok
      };
    }
    const matchArr = statusRegex.exec(responseBody.status);
    return {
      raw: result,
      href: responseBody.href,

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The OAuth helper logs sensitive token material via debug statements, including generated Basic auth tokens and fetched access tokens. If debug output is enabled or collected centrally, credentials can be exposed to logs, enabling account takeover for email/calendar data and actions.

Content

Scanner excerpt · dist/cli.js (reported line 10662)May include surrounding context.

js
const tokens = await response.json();
    return tokens;
  }
  debug(`Refresh access token failed: ${await response.text()}`);
  return {};
};
var getOauthHeaders = async (credentials, fetchOptions) => {

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The send_email handler sends outbound email using user-supplied recipients and content, but the code provides no confirmation prompt or explicit warning before performing this irreversible external action. Because this operation can contact third parties and transmit user data, a user disclosure is expected in the code path.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The delete_email handler moves an email into the Trash, altering user mailbox state, but does so without any confirmation prompt or visible warning. Even though it is implemented as a move to trash rather than permanent deletion, it is still a destructive user-data action that should be disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reply_email handler constructs and sends a reply, potentially including reply-all recipients from the original message, without any confirmation or warning. This can expose message content to unintended recipients and is an external, irreversible communication action.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The delete_event handler removes a calendar event from the remote calendar service with no confirmation or visible warning. This is a destructive change to user data and should not occur silently.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bulk_delete_emails handler performs destructive changes on multiple messages at once, yet provides no user-facing warning or confirmation. Bulk actions amplify the risk of accidental data loss and therefore need especially clear disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

Bulk deletion is a high-risk destructive capability because a mistaken invocation, prompt injection, or ambiguous user instruction can remove many messages at once and materially impact data availability. In a mail-management skill, documenting this action without a prominent warning or confirmation expectation increases the chance of unsafe automated use.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Bulk email deletion magnifies the same unsafe pattern by allowing many messages to be removed in one call without confirmation or scoped safeguards. In the context of an email-management skill, this significantly increases blast radius from prompt injection, scripting mistakes, or compromised callers, potentially causing large-scale data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

Bulk deletion enables moving many emails to trash in one operation without any built-in guardrails, preview, or confirmation point in the tool interface. In an agentic context, this increases the blast radius of mistakes or prompt-induced misuse, allowing large-scale mailbox modification from a single action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README lists tools for sending email, moving email, and deleting email, which can affect user data or perform external actions, but it does not explicitly warn users that these actions may modify mailbox contents or send messages on their behalf. Although these actions are part of the skill's purpose, the markdown guidance should still disclose potentially destructive or privacy-impacting behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README documents tools to create, update, and delete calendar events, including reminders, but does not provide a user-facing warning that these operations will change calendar data and may remove events. For markdown files, omission of warnings about behaviors affecting user data or system state should be flagged.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The documentation explicitly recommends creating a persistent .env file containing long-lived Fastmail credentials. Persisting secrets on disk increases the attack window compared with ephemeral environment injection, and in this skill the persisted secrets enable ongoing access to email and calendar data.

Content

Scanner excerpt · README.md (reported line 76)May include surrounding context.

export FASTMAIL_PASSWORD="your-app-password-here"

text

Or create a `.env` file:

```bash
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises capabilities that require access to environment variables and network services, but it does not declare any tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it harder for operators and users to understand what the skill is authorized to access before running it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill can send email and respond to invitations on the user's behalf, but the description does not warn that these are external, state-changing actions. Without prominent disclosure and confirmation, the skill could be used to perform unintended communications or commitments that affect other people and systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents destructive actions such as deleting emails and deleting calendar events without warning about consequences, confirmation requirements, or reversibility. In a high-trust assistant context, users may trigger bulk or irreversible changes unintentionally, leading to data loss or operational disruption.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for managing Fastmail email and calendar via JMAP and CalDAV APIs, but this bundled code also exposes full CardDAV address-book operations such as fetching, creating, updating, and deleting vCards. Contact/address-book management is a distinct capability not justified by the stated purpose and is broader than what the manifest says the skill is for.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · dist/cli.js (reported line 9002)May include surrounding context.

js
async getSession() {
    if (this.session)
      return this.session;
    const response = await fetch("https://api.fastmail.com/jmap/session", {
      headers: {
        Authorization: `Bearer ${this.token}`
      }

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/cli.js:1020

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/cli.js:10614