apple-mail

Fail

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Multiple scripts (e.g., mail-list.sh, mail-search.sh, mail-accounts.sh, mail-send.sh, mail-refresh.sh) directly interpolate user-provided arguments into AppleScript code blocks. This lack of sanitization allows for command injection, where a crafted input could escape the intended logic and execute arbitrary shell commands on the host system via the do shell script functionality in AppleScript.
  • [COMMAND_EXECUTION]: The scripts mail-fast-search.sh, mail-delete.sh, mail-read.sh, mail-mark-read.sh, and mail-mark-unread.sh are vulnerable to SQL injection because they interpolate variables like $QUERY and $MSG_ID directly into SQLite queries without proper escaping or parameterization.
  • [DATA_EXFILTRATION]: The mail-send.sh utility supports attaching arbitrary local files to outgoing emails. Because there are no restrictions or validations on the file paths provided, it can be abused to exfiltrate sensitive files, such as SSH keys, by sending them to an external address.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted content from incoming email subjects and bodies. This content is presented to the AI agent without sanitization or boundary markers, creating a risk where a malicious email could contain hidden instructions to manipulate the agent's behavior. Ingestion points: scripts/mail-read.sh, scripts/mail-list.sh, scripts/mail-fast-search.sh. Boundary markers: Absent; email content is provided as raw text. Capability inventory: Arbitrary shell command execution (via injection vulnerabilities), email sending, and local file access. Sanitization: Absent; scripts use simple string interpolation for system commands and database queries.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates and executes AppleScript and shell command strings at runtime using unsanitized user inputs, which is a significant security risk for unauthorized system access.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 25, 2026, 04:58 AM
Security Audit — agent-trust-hub — apple-mail