Back to skill

Security audit

邮件免费版

Security checks for vulnerabilities and agentic risk

Overview

This skill is for read-only email search, but it asks users to install and authenticate an unpinned third-party CLI with access to private mailbox data.

Before installing, verify the porteden CLI source and release integrity, review the exact Gmail/Outlook OAuth scopes it requests, avoid persistent environment-variable API keys, and remove the skill's write permission unless a specific write workflow is added and documented.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:110
Finding

Unverified Third-Party CLI Is Granted Access to Sensitive Mailbox Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 110–112
Vulnerability Type: Supply-chain risk from an unverified third-party dependency
Risk Level: Medium

Vulnerable Code

markdown
## 前置依赖

1. 安装 porteden CLI:`brew install porteden/tap/porteden`
2. 登录:`porteden auth login` 打开浏览器,凭证存入系统 keyring
3. 验证:`porteden auth status`

The installation command is also repeated at SKILL.md:34 and SKILL.md:172.

Technical Analysis

The Skill directs the user or agent to install porteden from the custom Homebrew tap porteden/tap. It then instructs the user to authenticate the installed program to Gmail or Outlook, with credentials stored through the system keyring.

No immutable version, formula revision, package checksum, release signature, authoritative source repository, or other integrity-verification mechanism is specified. Consequently, the code ultimately installed and executed can change after this Skill has been reviewed. A compromise of the tap, formula, release hosting infrastructure, or publisher account could therefore introduce malicious installation or runtime behavior.

This dependency operates across a high-sensitivity trust boundary: it receives access to private mailbox metadata and content and participates in the authentication flow. Although no malicious implementation is included in the audited project, the documented installation process does not adequately establish the integrity of the component receiving that access.

Attack Path

  1. An attacker compromises the custom Homebrew tap, its publisher account, the formula, or an artifact referenced by the formula.

  2. The attacker modifies the package or installation definition to distribute a malicious porteden executable.

  3. A user or agent follows the Skill instructions and runs:

    bash
    brew install porteden/tap/porteden
    
  4. The malicious executable runs with the privileges of the invoking user.

  5. The user follows the authentication instr ...[truncated 1035 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed, immutable version and, where possible, an immutable Homebrew formula revision or commit.
  2. Publish the authoritative source repository and official release location in the Skill documentation.
  3. Verify the downloaded artifact using a publisher signature or a documented SHA-256 checksum before execution.
  4. Review the Homebrew formula for installation hooks, dynamically retrieved resources, and mutable download URLs.
  5. Document the exact Gmail and Outlook authorization scopes requested by the CLI.
  6. Require least-privilege, read-only mailbox scopes consistent with the advertised functionality.
  7. Provide explicit procedures for revoking OAuth grants, invalidating API keys, and removing keyring credentials.
  8. Recommend installation and initial verification in a restricted environment before granting access to a production mailbox.
  9. Remove the declared write tool permission if it is unnecessary for the read-only workflow.
  10. Resolve the inconsistent credential variable names (API_KEY and PE_API_KEY) and document secure secret handling without printing or persisting secrets in plaintext.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
77% confidence
Finding

The skill explicitly instructs users to fall back from OS keyring storage to a raw PE_API_KEY environment variable when keyring access is unavailable. Environment variables are commonly exposed to subprocesses, shell history, crash dumps, CI logs, and other local users/processes, so normalizing this fallback weakens credential protection for a skill that accesses private email data. In this context, the danger is elevated because compromised mail access can expose sensitive communications, reset links, invoices, and other high-value data.

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
### 4. keyring 不可用

- **现象**:`porteden auth login` 报 keyring access denied
- **处理**:检查系统钥匙串服务,或改用 `PE_API_KEY` 环境变量

### 5. 正文过大导致 token 超限

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest uses Chinese-only user-facing metadata such as displayName, summary, and description, while the rest of the file mixes languages and does not state that the skill is region-specific. This can violate a language/locale policy requiring user choice or explicit justification for locale constraints.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill repeatedly claims it only supports read-only mail operations, such as listing, searching, and fetching messages. However, the documented workflow also instructs users to run porteden auth login and porteden auth logout, which are state-changing account/session operations; this contradicts a strict reading of the read-only positioning in the documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.