apple-mail
Fail
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Multiple scripts (e.g.,
mail-list.sh,mail-search.sh,mail-accounts.sh,mail-send.sh,mail-refresh.sh) directly interpolate user-provided arguments into AppleScript code blocks. This lack of sanitization allows for command injection, where a crafted input could escape the intended logic and execute arbitrary shell commands on the host system via thedo shell scriptfunctionality in AppleScript. - [COMMAND_EXECUTION]: The scripts
mail-fast-search.sh,mail-delete.sh,mail-read.sh,mail-mark-read.sh, andmail-mark-unread.share vulnerable to SQL injection because they interpolate variables like$QUERYand$MSG_IDdirectly into SQLite queries without proper escaping or parameterization. - [DATA_EXFILTRATION]: The
mail-send.shutility supports attaching arbitrary local files to outgoing emails. Because there are no restrictions or validations on the file paths provided, it can be abused to exfiltrate sensitive files, such as SSH keys, by sending them to an external address. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted content from incoming email subjects and bodies. This content is presented to the AI agent without sanitization or boundary markers, creating a risk where a malicious email could contain hidden instructions to manipulate the agent's behavior. Ingestion points:
scripts/mail-read.sh,scripts/mail-list.sh,scripts/mail-fast-search.sh. Boundary markers: Absent; email content is provided as raw text. Capability inventory: Arbitrary shell command execution (via injection vulnerabilities), email sending, and local file access. Sanitization: Absent; scripts use simple string interpolation for system commands and database queries. - [DYNAMIC_EXECUTION]: The skill dynamically generates and executes AppleScript and shell command strings at runtime using unsanitized user inputs, which is a significant security risk for unauthorized system access.
Recommendations
- AI detected serious security threats
Audit Metadata