T09 · Insecure Skill Coding Practices
- Location
scripts/email_client.py:601- Finding
Arbitrary File Write Through Untrusted Attachment Filenames
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This email skill is mostly purpose-aligned, but it handles mailbox credentials, sends and reads mail, installs unsafe dependencies, and has local file risks that deserve review before use.
Install only if you are comfortable granting the skill access to your mailbox and local files. Use app-specific mail passwords, avoid storing real secrets in a committed .env file, review every send or attachment-save action, and fix the requirements.txt and attachment filename handling before routine use.
scripts/email_client.py:601Arbitrary File Write Through Untrusted Attachment Filenames
scripts/email_client.py:493IMAP Search-Criteria Injection Through Unsanitized Search Values
requirements.txt:1Standard-Library Module Names Declared as Installable Dependencies
SKILL.md:20Mailbox Credentials Stored in a Predictable Plaintext Skill File
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Email Operations Skill - 环境变量配置示例
# 请复制此文件为 .env 并填写实际值
# ==================== 必填项 ====================
# 邮箱地址
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""
Email Client - IMAP/SMTP 邮件客户端
支持 Gmail, QQ, Outlook 等主流邮件服务
凭证从技能目录下的 .env 文件读取
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def _load_env(self, skill_dir: str):
"""从技能目录加载 .env 文件"""
env_path = os.path.join(skill_dir, ".env")
if not os.path.exists(env_path):
return
The skill exposes high-impact capabilities—reading credentials from a local .env file, reading local files/attachments, and making IMAP/SMTP network connections—but does not declare any tool scope or permission boundaries. In an agent environment, this weakens least-privilege controls and can allow unintended mailbox access, attachment exfiltration, or outbound email actions without explicit policy gating.
The trigger criteria are overly broad: the skill may activate whenever a user mentions general email-related tasks, even without clearly intending mailbox access or message sending. In practice, this can cause an agent to invoke a high-privilege skill in ambiguous contexts, increasing the risk of unintended access to sensitive emails or accidental outbound messages.
The documentation describes sensitive operations—reading email content, downloading attachments, and sending messages—but does not warn users about privacy, confidentiality, or potential data exfiltration risks. Because email often contains highly sensitive personal and business data, the lack of user-facing risk disclosure increases the chance of unsafe use and uninformed consent.
This JSON eval file contains only Chinese prompts for the skill's expected interaction pattern, which implies a fixed language requirement. Under the policy rule, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.
Natural-language strings throughout the file, including the module description, docstrings, CLI errors, and output messages, are presented in Chinese only. This effectively forces a specific language/locale on users without an explicit opt-in or alternative, which matches the language-policy violation criteria.
The skill can read arbitrary local files via --body-file, --html-body-file, and attachment paths, then include their contents in outbound email. In an agent setting, this expands the skill from mailbox interaction into local file exfiltration, which is especially risky because the manifest does not clearly scope or constrain filesystem access.
save_attachment writes email attachments to a caller-controlled save_path, allowing arbitrary local file writes within the process's permissions. In an agent environment this creates an unnecessary filesystem write primitive beyond stated mailbox operations, which can be abused to place files in sensitive locations or persist untrusted content locally.
Attachments are written to disk without any user-visible notice, confirmation, or disclosure that a filesystem write is occurring. In an agent context, silent local writes increase the risk of storing malicious or sensitive content on the host and can violate user expectations about the skill's behavior.
文件顶部描述全文以中文编写,且未说明这是特定地区/语言环境专用技能,也未提供用户可选语言。按照该规则,若技能在自然语言层面默认强制特定语言而无用户选择,属于语言/locale 策略风险。
This requirements file includes user-facing comments only in Chinese, such as the installation guidance on L2 and explanatory notes on L8-L9. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language choice is provided.
The codebase includes a save_attachment capability that materially extends behavior beyond the manifest’s examples of viewing content and attachment information. This is a semantic mismatch because the manifest frames attachments as information retrieval, while the implementation includes exporting attachment files to disk.
No suspicious patterns detected.