qq-email
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses external email content which can be used as an attack vector to influence the agent's behavior.
- Ingestion points:
scripts/receive.js(subject and summary) andscripts/get-body.js(full body). - Boundary markers: The instructions do not define clear delimiters to separate email content from agent instructions.
- Capability inventory: The agent has access to
Bash,Read, andWritetools across the provided scripts. - Sanitization:
scripts/get-body.jsuses a basic regex-basedhtmlToTextfunction for display, but this does not prevent the agent from interpreting the resulting text as instructions. - [COMMAND_EXECUTION]: The skill requires the use of the
Bashtool to execute Node.js scripts that perform network requests to external mail servers. - [DATA_EXFILTRATION]: The scripts
scripts/get-body.jsandscripts/receive.jsconfigure the IMAP connection withrejectUnauthorized: false. This disables SSL/TLS certificate verification, creating a vulnerability to Man-in-the-Middle (MitM) attacks where a network attacker could intercept theQQ_EMAIL_AUTH_CODEor email data.
Audit Metadata