T03 · Remote Payload Retrieval and Execution
- Location
README.md:246- Finding
Remote installer is downloaded and executed without verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Fastmail skill does what it claims, but it handles very sensitive email and calendar actions with weak safeguards and insecure setup guidance.
Review this carefully before installing. Use a dedicated, narrowly scoped Fastmail token and app password if possible, avoid storing them in shell profiles or committed .env files, do not run the curl-to-bash installer blindly, and require explicit review before any send, reply-all, delete, bulk delete, calendar deletion, or invitation response action.
README.md:246Remote installer is downloaded and executed without verification
scripts/jmap-client.ts:28Fastmail bearer token can be forwarded to an unvalidated session-provided URL
scripts/tools/calendar.ts:263Unescaped user input permits iCalendar property injection
README.md:65Documentation encourages plaintext persistence of long-lived Fastmail credentials
package.json:10Unpinned dependency resolution is performed without a committed lockfile
The README instructs users to place a full-access Fastmail API token into a local .env file. While common in development, this increases the risk of credential exposure through accidental commits, backups, local file disclosure, or unsafe sharing, especially because the token grants broad mailbox access.
Or create a .env file:
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env
echo "FASTMAIL_USERNAME=your-email@fastmail.com" >> .env
echo "FASTMAIL_PASSWORD=your-app-password-here" >> .env
The README instructs storing the Fastmail username in .env alongside other credentials. By itself the username is less sensitive, but colocating account identifiers with secrets in a plaintext file increases the usefulness of any file disclosure or accidental repository leak.
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env
echo "FASTMAIL_USERNAME=your-email@fastmail.com" >> .env
echo "FASTMAIL_PASSWORD=your-app-password-here" >> .env
The README instructs users to store a Fastmail app password in a plaintext .env file. This is sensitive credential material that can enable unauthorized calendar access if the file is exposed via source control, endpoint compromise, shell tooling, or logs; the skill context makes this more dangerous because the account may contain private scheduling and relationship data.
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env
echo "FASTMAIL_USERNAME=your-email@fastmail.com" >> .env
echo "FASTMAIL_PASSWORD=your-app-password-here" >> .env
Then reload:
The README recommends installing Bun with curl ... | bash, which executes a remotely fetched script without prior verification. If the transport endpoint, CDN, DNS, or upstream distribution is compromised, users could run attacker-controlled code directly on their system.
### Requirements
- [Bun](https://bun.sh/) - JavaScript runtime (install with `curl -fsSL https://bun.sh/install | bash`)
## Troubleshooting
This second mismatch finding indicates the skill claims email, reminders, RSVP handling, and timezone auto-detection, while the observed implementation lacks those features and may rely on undeclared authentication behavior. Such overclaiming can mislead users into supplying API tokens, usernames, and passwords to a tool whose real behavior is insufficiently disclosed, increasing the risk of credential misuse or unsafe execution.
This second mismatch finding indicates the skill claims email, reminders, RSVP handling, and timezone auto-detection, while the observed implementation lacks those features and may rely on undeclared authentication behavior. Such overclaiming can mislead users into supplying API tokens, usernames, and passwords to a tool whose real behavior is insufficiently disclosed, increasing the risk of credential misuse or unsafe execution.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
+value, offset = offset >>> 0, !noAssert)
checkIEEE754(buf, value, offset, 4, 340282346638528860000000000000000000000, -340282346638528860000000000000000000000);
return write(buf, value, offset, littleEndian, 23, 4), offset + 4;
}
function writeDouble(buf, value, offset, littleEndian, noAssert) {
if (value = +value, offset = offset >>> 0, !noAssert)
checkIEEE754(buf, value, offset, 8, 179769313486231570000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000, -179769313486231570000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
ok: davResponse.ok
};
}
const matchArr = statusRegex.exec(responseBody.status);
return {
raw: result,
href: responseBody.href,
The OAuth helper logs sensitive token material via debug statements, including generated Basic auth tokens and fetched access tokens. If debug output is enabled or collected centrally, credentials can be exposed to logs, enabling account takeover for email/calendar data and actions.
const tokens = await response.json();
return tokens;
}
debug(`Refresh access token failed: ${await response.text()}`);
return {};
};
var getOauthHeaders = async (credentials, fetchOptions) => {
The send_email handler sends outbound email using user-supplied recipients and content, but the code provides no confirmation prompt or explicit warning before performing this irreversible external action. Because this operation can contact third parties and transmit user data, a user disclosure is expected in the code path.
The delete_email handler moves an email into the Trash, altering user mailbox state, but does so without any confirmation prompt or visible warning. Even though it is implemented as a move to trash rather than permanent deletion, it is still a destructive user-data action that should be disclosed.
The reply_email handler constructs and sends a reply, potentially including reply-all recipients from the original message, without any confirmation or warning. This can expose message content to unintended recipients and is an external, irreversible communication action.
The delete_event handler removes a calendar event from the remote calendar service with no confirmation or visible warning. This is a destructive change to user data and should not occur silently.
The bulk_delete_emails handler performs destructive changes on multiple messages at once, yet provides no user-facing warning or confirmation. Bulk actions amplify the risk of accidental data loss and therefore need especially clear disclosure.
Bulk deletion is a high-risk destructive capability because a mistaken invocation, prompt injection, or ambiguous user instruction can remove many messages at once and materially impact data availability. In a mail-management skill, documenting this action without a prominent warning or confirmation expectation increases the chance of unsafe automated use.
Bulk email deletion magnifies the same unsafe pattern by allowing many messages to be removed in one call without confirmation or scoped safeguards. In the context of an email-management skill, this significantly increases blast radius from prompt injection, scripting mistakes, or compromised callers, potentially causing large-scale data loss.
Bulk deletion enables moving many emails to trash in one operation without any built-in guardrails, preview, or confirmation point in the tool interface. In an agentic context, this increases the blast radius of mistakes or prompt-induced misuse, allowing large-scale mailbox modification from a single action.
The README lists tools for sending email, moving email, and deleting email, which can affect user data or perform external actions, but it does not explicitly warn users that these actions may modify mailbox contents or send messages on their behalf. Although these actions are part of the skill's purpose, the markdown guidance should still disclose potentially destructive or privacy-impacting behaviors.
The README documents tools to create, update, and delete calendar events, including reminders, but does not provide a user-facing warning that these operations will change calendar data and may remove events. For markdown files, omission of warnings about behaviors affecting user data or system state should be flagged.
The documentation explicitly recommends creating a persistent .env file containing long-lived Fastmail credentials. Persisting secrets on disk increases the attack window compared with ephemeral environment injection, and in this skill the persisted secrets enable ongoing access to email and calendar data.
export FASTMAIL_PASSWORD="your-app-password-here"
Or create a `.env` file:
```bash
echo "FASTMAIL_API_TOKEN=your-api-token-here" >> .env
The skill advertises capabilities that require access to environment variables and network services, but it does not declare any tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it harder for operators and users to understand what the skill is authorized to access before running it.
The skill can send email and respond to invitations on the user's behalf, but the description does not warn that these are external, state-changing actions. Without prominent disclosure and confirmation, the skill could be used to perform unintended communications or commitments that affect other people and systems.
The skill documents destructive actions such as deleting emails and deleting calendar events without warning about consequences, confirmation requirements, or reversibility. In a high-trust assistant context, users may trigger bulk or irreversible changes unintentionally, leading to data loss or operational disruption.
The manifest describes a skill for managing Fastmail email and calendar via JMAP and CalDAV APIs, but this bundled code also exposes full CardDAV address-book operations such as fetching, creating, updating, and deleting vCards. Contact/address-book management is a distinct capability not justified by the stated purpose and is broader than what the manifest says the skill is for.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
async getSession() {
if (this.session)
return this.session;
const response = await fetch("https://api.fastmail.com/jmap/session", {
headers: {
Authorization: `Bearer ${this.token}`
}
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal