Back to skill

Security audit

Email Send

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple email-sending helper with expected SMTP and package-install behavior, though users should treat any email content or attachments as external disclosure.

Before installing, confirm you are comfortable configuring SMTP credentials in the environment and sending message bodies, recipients, CC/BCC, and any files externally by email. Treat the attachment option cautiously because the artifact does not clearly show how attachments are implemented.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly facilitates transmitting user-provided content to external email recipients, and it mentions CC/BCC and attachments without any warning about data exfiltration, privacy, or recipient validation. In an agent context, this increases the risk of unintentionally sending sensitive data outside the local environment, especially if users assume the action is low-risk because it is framed as a convenience skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation lists --attach <file> as an available option, but the skill only declares msmtp as a required binary and all examples invoke msmtp directly. This is an active intent/documentation mismatch because the documented capability is not implemented by the described command usage.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

Install

bash
sudo dnf install msmtp

Static analysis

No suspicious patterns detected.