Back to skill

Security audit

Email Operations

Security checks for vulnerabilities and agentic risk

Overview

This email skill is mostly purpose-aligned, but it handles mailbox credentials, sends and reads mail, installs unsafe dependencies, and has local file risks that deserve review before use.

Install only if you are comfortable granting the skill access to your mailbox and local files. Use app-specific mail passwords, avoid storing real secrets in a committed .env file, review every send or attachment-save action, and fix the requirements.txt and attachment filename handling before routine use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/email_client.py:601
Finding

Arbitrary File Write Through Untrusted Attachment Filenames

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/email_client.py:493
Finding

IMAP Search-Criteria Injection Through Unsanitized Search Values

Content
View full analysis
Remediation
View remediation
str: if any(ch in value for ch in ("\r", "\n", "\x00")): raise ValueError("Invalid IMAP search value") return '"' + value.replace("\\", "\\\\").replace('"', '\\"') + '"' ``` ]]>

T08 · Insecure Dependencies

Error
Location
requirements.txt:1
Finding

Standard-Library Module Names Declared as Installable Dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Mailbox Credentials Stored in a Predictable Plaintext Skill File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .env (reported line 2)May include surrounding context.

text
# Email Operations Skill - 环境变量配置示例
# 请复制此文件为 .env 并填写实际值

# ==================== 必填项 ====================
# 邮箱地址

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/email_client.py (reported line 4)May include surrounding context.

python
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/email_client.py (reported line 31)May include surrounding context.

python
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/email_client.py (reported line 38)May include surrounding context.

python
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/email_client.py (reported line 53)May include surrounding context.

python
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/email_client.py (reported line 60)May include surrounding context.

python
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/email_client.py (reported line 61)May include surrounding context.

python
def _load_env(self, skill_dir: str):
        """从技能目录加载 .env 文件"""
        env_path = os.path.join(skill_dir, ".env")
        if not os.path.exists(env_path):
            return

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes high-impact capabilities—reading credentials from a local .env file, reading local files/attachments, and making IMAP/SMTP network connections—but does not declare any tool scope or permission boundaries. In an agent environment, this weakens least-privilege controls and can allow unintended mailbox access, attachment exfiltration, or outbound email actions without explicit policy gating.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger criteria are overly broad: the skill may activate whenever a user mentions general email-related tasks, even without clearly intending mailbox access or message sending. In practice, this can cause an agent to invoke a high-privilege skill in ambiguous contexts, increasing the risk of unintended access to sensitive emails or accidental outbound messages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation describes sensitive operations—reading email content, downloading attachments, and sending messages—but does not warn users about privacy, confidentiality, or potential data exfiltration risks. Because email often contains highly sensitive personal and business data, the lack of user-facing risk disclosure increases the chance of unsafe use and uninformed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON eval file contains only Chinese prompts for the skill's expected interaction pattern, which implies a fixed language requirement. Under the policy rule, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings throughout the file, including the module description, docstrings, CLI errors, and output messages, are presented in Chinese only. This effectively forces a specific language/locale on users without an explicit opt-in or alternative, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill can read arbitrary local files via --body-file, --html-body-file, and attachment paths, then include their contents in outbound email. In an agent setting, this expands the skill from mailbox interaction into local file exfiltration, which is especially risky because the manifest does not clearly scope or constrain filesystem access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

save_attachment writes email attachments to a caller-controlled save_path, allowing arbitrary local file writes within the process's permissions. In an agent environment this creates an unnecessary filesystem write primitive beyond stated mailbox operations, which can be abused to place files in sensitive locations or persist untrusted content locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Attachments are written to disk without any user-visible notice, confirmation, or disclosure that a filesystem write is occurring. In an agent context, silent local writes increase the risk of storing malicious or sensitive content on the host and can violate user expectations about the skill's behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

文件顶部描述全文以中文编写,且未说明这是特定地区/语言环境专用技能,也未提供用户可选语言。按照该规则,若技能在自然语言层面默认强制特定语言而无用户选择,属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This requirements file includes user-facing comments only in Chinese, such as the installation guidance on L2 and explanatory notes on L8-L9. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language choice is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The codebase includes a save_attachment capability that materially extends behavior beyond the manifest’s examples of viewing content and attachment information. This is a semantic mismatch because the manifest frames attachments as information retrieval, while the implementation includes exporting attachment files to disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.