Back to plugin

Security audit

OpenMail

Security checks for vulnerabilities and agentic risk

Overview

This skill gives an agent a real OpenMail inbox and can send or reply to email, but that behavior is clearly disclosed and aligned with its purpose.

Install only if you want your agent to have real email capability. Use notify or tool mode for human review before replies, prefer inbox-scoped keys unless pod-wide access is needed, and treat inbound email and attachments as untrusted.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description includes broad trigger phrases like 'reach out to them', 'contact support', 'sign up', and 'wait for their reply', which can cause the email capability to activate from ambiguous user requests. Because this skill can send real external email, accidental invocation could lead to unintended contact, privacy exposure, or actions on third-party services without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/openmail/SKILL.md (reported line 120)May include surrounding context.

md
- Use context you have. Told the user about mail from alice@example.com and
  they say "reply to her"? You know the sender and thread. Just do it.
- Never ask the user for ids or addresses you can look up
  (`threads list`, `threads get`).
- Reply in the existing thread. New threads only when explicitly asked.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/cli.js:62
Evidence
const child = spawn(process.execPath, [resolveBundledCliPath(), ...args], {