email-manager

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Outsider-authored email body text is fetched at runtime from the user’s IMAP mailbox (e.g., scripts/imap.jssearchMessages()msg.on('body')parseEmail() via mailparser.simpleParser), and that parsed free text is then returned/printed as JSON into the agent context.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 12:26 PM
Issues
1
Security Audit — snyk — email-manager