skills/hk-hub/agentskills/qq-email/Gen Agent Trust Hub

qq-email

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses external email content which can be used as an attack vector to influence the agent's behavior.
  • Ingestion points: scripts/receive.js (subject and summary) and scripts/get-body.js (full body).
  • Boundary markers: The instructions do not define clear delimiters to separate email content from agent instructions.
  • Capability inventory: The agent has access to Bash, Read, and Write tools across the provided scripts.
  • Sanitization: scripts/get-body.js uses a basic regex-based htmlToText function for display, but this does not prevent the agent from interpreting the resulting text as instructions.
  • [COMMAND_EXECUTION]: The skill requires the use of the Bash tool to execute Node.js scripts that perform network requests to external mail servers.
  • [DATA_EXFILTRATION]: The scripts scripts/get-body.js and scripts/receive.js configure the IMAP connection with rejectUnauthorized: false. This disables SSL/TLS certificate verification, creating a vulnerability to Man-in-the-Middle (MitM) attacks where a network attacker could intercept the QQ_EMAIL_AUTH_CODE or email data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — qq-email