Back to skill

Security audit

gmail-wiki-ingest

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Gmail-to-wiki triage integration that reads limited email data and relies on server-side controls for writes and auto-ingest decisions.

Install only if you are comfortable with a daily HiJavis workflow that reads Gmail metadata, may read up to 12 full staged threads per run, and can write trusted-sender mail into your wiki automatically with server-side controls and undo. The artifact says Gmail access is read-only and controlled by the HiJavis enable switch.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk does not itself implement the skill runtime; it is a test file for that implementation. However, judged by behavior exercised and asserted, it largely aligns with the declared purpose: it covers the four I/O commands (fetch, content, submit, report), bearer-token gateway use, body-read cap of 12, always-report behavior including empty fetches, and server-side ownership of outcome fields. The main mismatch is that this chunk also enforces additional responsibilities not disclosed in the description: documentation-wire-contract validation, CLI/exit-code semantics, and detailed markdown sanitization/report rendering rules. These are material capabilities of the tested bundle but ancillary to the core email-triage purpose. So there is a mismatch, though it is more an under-description of supporting/contract-enforcement behavior than a completely different primary purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 387)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 442)May include surrounding context.

md
node scripts/gmail-wiki-ingest.js fetch ──► metadata + knowledge model

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger list includes very broad natural-language phrases such as "ingest my email" and "sync my inbox to the wiki," which could be invoked in ordinary conversation rather than as an intentional command. In a skill that reads private Gmail metadata and may process message bodies, accidental invocation increases the risk of unintended access to sensitive email content and unplanned ingestion actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 314)May include surrounding context.

md
|---|---|
| **LOW** | no card, no page. An auto-discard row on the ledger, `source='auto'`. |
| **MIDDLE** | a pending `SkillData` row — the review card the user answers with Confirm / Discard. This is the day-one behavior and still the common case. |
| **HIGH** | auto-confirmed and distilled into the wiki on the spot, with an undo offered on the card for a bounded window. |

**The score alone never reaches HIGH.** The measured bands overlap — true-keep
mail scores as low as 0.70, unwanted mail as high as 0.80 — so no cut point

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/banding-and-trust.md (reported line 25)May include surrounding context.

md
|---|---|
| **LOW** | no card, no page. An auto-discard row on the ledger, `source='auto'`. |
| **MIDDLE** | a pending `SkillData` row — the review card the user answers with Confirm / Discard. This is the day-one behavior and still the common case. |
| **HIGH** | auto-confirmed and distilled into the wiki on the spot, with an undo offered on the card for a bounded window. |

**The score alone never reaches HIGH.** The measured bands overlap — true-keep
mail scores as low as 0.70, unwanted mail as high as 0.80 — so no cut point

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/banding-and-trust.md (reported line 56)May include surrounding context.

md
|---|---|
| **LOW** | no card, no page. An auto-discard row on the ledger, `source='auto'`. |
| **MIDDLE** | a pending `SkillData` row — the review card the user answers with Confirm / Discard. This is the day-one behavior and still the common case. |
| **HIGH** | auto-confirmed and distilled into the wiki on the spot, with an undo offered on the card for a bounded window. |

**The score alone never reaches HIGH.** The measured bands overlap — true-keep
mail scores as low as 0.70, unwanted mail as high as 0.80 — so no cut point

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/banding-and-trust.md (reported line 91)May include surrounding context.

md
|---|---|
| **LOW** | no card, no page. An auto-discard row on the ledger, `source='auto'`. |
| **MIDDLE** | a pending `SkillData` row — the review card the user answers with Confirm / Discard. This is the day-one behavior and still the common case. |
| **HIGH** | auto-confirmed and distilled into the wiki on the spot, with an undo offered on the card for a bounded window. |

**The score alone never reaches HIGH.** The measured bands overlap — true-keep
mail scores as low as 0.70, unwanted mail as high as 0.80 — so no cut point

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README lists both English and Chinese trigger phrases, but it does not explain whether language choice is user-selectable or how locale handling works. This can create ambiguity around language behavior and may conflict with organizational expectations that language or locale be user-driven unless explicitly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest lists Chinese trigger phrases alongside English ones, but the file does not state that multilingual triggering is optional or user-configurable. Because language/locale policy findings apply to natural-language constraints across all file types, this can be read as imposing specific locale behavior without explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description and keywords include Chinese-only trigger phrases ('整理邮件', '邮件入库') alongside English ones, but the manifest does not say the skill is region-specific or that users can choose/opt into locale behavior. Under the stated policy, forcing or assuming a specific language/locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/cli.test.js:315