Back to skill

Security audit

邮件

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real email-management helper, but it grants powerful mailbox access while its top-level description and install/auth guidance are too broad and inconsistent.

Review before installing. Use only for explicit email tasks, prefer browser login over direct token or environment variables, verify the porteden CLI source and version before installation, and require manual confirmation before any send, reply, forward, modify, or delete action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:41
Finding

Unpinned and Unverified Third-Party CLI Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:41-45
Vulnerability Type: Supply-chain risk from an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

bash
brew install porteden/tap/porteden
# or
go install 相关技术文档

Related installation and authentication instructions also appear at SKILL.md:120-126:

text
1. Install porteden CLI: `brew install porteden/tap/porteden`
2. Login (choose one):
   - Browser login (recommended): `porteden auth login`
   - Direct token: `porteden auth login --token <key>`
   - Environment variable: set `PE_API_KEY`

Technical Analysis

The Skill instructs the Agent to install and execute the third-party porteden CLI from a Homebrew tap without pinning an immutable release, verifying a checksum or signature, or identifying a trusted source repository. The alternative Go installation command is incomplete and provides neither a module path nor a fixed version.

The CLI is security-sensitive because it receives mailbox credentials and is authorized to read, send, reply to, forward, modify, and delete email. If the package source, tap, distribution account, or latest release is compromised, installation could introduce code different from the version originally reviewed.

This finding identifies a supply-chain weakness; the reviewed project does not contain evidence that the current package is malicious.

Attack Path

  1. An attacker compromises the third-party tap, package publication account, or upstream release channel.
  2. The attacker publishes a modified package under the expected dependency name.
  3. A user invokes the Skill on a system where porteden is not installed.
  4. The Agent follows the documented unpinned installation command.
  5. The package manager retrieves and executes the attacker-controlled version.
  6. The user authenticates the CLI to a Gmail, Outlook, or Exchange mailbox.
  7. The compromised CLI captures credentials or performs unauthorized mailbox ope ...[truncated 616 chars]
Remediation
View remediation

Remediation Suggestions

  1. Identify and link the authoritative upstream source repository and package documentation.
  2. Pin installation to a reviewed, immutable release rather than implicitly installing the latest version.
  3. Publish and verify a cryptographic checksum or signed release artifact before execution.
  4. Replace the malformed Go example with a complete module path and fixed version, such as module/path@vX.Y.Z, after verifying the actual upstream module.
  5. Document the package publisher, expected signing identity, required mailbox scopes, and expected network destinations.
  6. Prefer installation through a trusted package repository with reproducible builds and provenance attestations.
  7. Re-audit the dependency before updating the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:123
Finding

Mailbox Token Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:123-126
Vulnerability Type: Sensitive credential passed as a process argument
Risk Level: Medium

Vulnerable Code

text
2. Login (choose one):
   - Browser login (recommended): `porteden auth login`
   - Direct token: `porteden auth login --token <key>` and store it in the keyring
   - Environment variable: set `PE_API_KEY`; the CLI uses it automatically without login

Technical Analysis

The documented direct-token workflow places a mailbox credential in a command-line argument. After a user replaces the placeholder with a real token, the secret may be exposed through:

  • Shell history.
  • Agent conversation or execution transcripts.
  • Terminal session recording.
  • Process inspection facilities.
  • Audit, debugging, or command telemetry.
  • Error reports that reproduce the executed command.

Storing the token in a keyring after execution does not prevent exposure that occurs while constructing, logging, or running the command. Whether process arguments are visible to other users depends on the operating system and its security configuration, but shell and Agent histories remain relevant exposure channels.

Attack Path

  1. A user follows the direct-token authentication example.
  2. The user or Agent substitutes a real mailbox token for the placeholder.
  3. The complete command is recorded in shell history, an Agent transcript, process telemetry, or another logging channel.
  4. An attacker or unauthorized local user obtains access to that record or inspects the process while it is running.
  5. The attacker extracts the token.
  6. The attacker uses the token against the associated service or CLI until it expires or is revoked.

Impact Assessment

The attacker may obtain the mailbox permissions associated with the exposed token. Depending on the token's granted scopes, this could include:

  • Reading email content and mailbox metadata.
  • Searching or enumerating messages.
  • Sending, ...[truncated 332 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the command-line token example.
  2. Prefer browser-based OAuth authentication with narrowly scoped authorization.
  3. If direct token entry is required, accept it through an interactive hidden prompt or standard input rather than a process argument.
  4. Ensure the CLI never logs, echoes, or includes credentials in errors or diagnostic output.
  5. Disable shell history for any unavoidable secret-entry operation and clear affected history and Agent transcripts.
  6. Apply the narrowest possible provider scopes and use short-lived credentials where supported.
  7. Document immediate token revocation and rotation procedures for suspected exposure.
  8. Avoid placing secrets in environment variables when stronger OS-backed credential input mechanisms are available, because environments can also leak through child processes, diagnostics, and process inspection.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

md
### 6. keyring 不可用

- **现象**:`porteden auth login` 报 keyring access denied
- **处理**:macOS 检查 Keychain 访问权限;Linux 确认 `gnome-keyring` 或 `kwallet` 服务运行;Windows 检查 Credential Manager 服务;或改用 `PE_API_KEY` 环境变量

### 7. 正文过大导致 token 超限

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The visible metadata and descriptive instructions are presented in Chinese, but the document does not offer a language choice or state that the skill is intentionally limited to Chinese-speaking users. This creates a locale/language policy issue because the skill effectively imposes one language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes the skill as a generic productivity/automation tool, but the actual functionality includes reading, sending, modifying, and deleting email through authenticated accounts. That mismatch hides the privileged nature of the capability, making overbroad or accidental invocation more likely and increasing the risk of data exposure, unauthorized communication, or message tampering.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation language is so broad that it could match many unrelated productivity or workflow-optimization requests, causing the agent to load a powerful email skill when mailbox access was not intended. Because the skill has authenticated read/write capabilities, overbroad triggering materially raises the risk of unnecessary access to sensitive communications and unintended email actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document states that send/reply/forward/delete/modify actions require human confirmation, but the broader automation-oriented metadata does not preserve that constraint. In an agent ecosystem, that omission can cause the skill to be invoked for autonomous workflows that perform irreversible or externally visible email actions without an explicit approval step.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself in one section as pure Markdown/natural-language driven while elsewhere declaring EXEC capability and providing concrete shell commands. This inconsistency can mislead agents, reviewers, or policy gates into treating the skill as lower risk than it is, increasing the chance that privileged command execution against email accounts occurs without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.