apple-mail

Warn

Audited by Socket on Sep 25, 2026

4 alerts found:

SecurityAnomalyx3
SecurityMEDIUM
scripts/mail-reply.sh

This is a mail-reply utility with a consequential AppleScript injection weakness: untrusted arguments are interpolated into executable AppleScript with incomplete escaping. An attacker able to control its arguments could potentially alter the script and cause unintended Mail actions. The sending behavior itself matches the stated purpose; the fragment does not otherwise show clear malware behavior.

Confidence: 96%Severity: 72%
AnomalyLOW
scripts/mail-delete.sh

The script performs the stated task of deleting Mail messages, but it builds SQL, Python, and AppleScript source using unescaped external or database-derived values. This creates injection risks, especially if arguments or Mail database contents are attacker-controlled. No clear evidence of malware or data exfiltration appears in the code.

Confidence: 97%Severity: 62%
AnomalyLOW
scripts/mail-read.sh

No overt malicious payload behavior (no networking, persistence, or system modification) is evident. However, the script has meaningful security/privacy risks: it outputs full email bodies to stdout (high privacy impact) and it uses unsafe dynamic interpolation of an unvalidated, user-controlled MSG_ID into a sqlite3 SQL statement and an AppleScript heredoc (injection/logic manipulation risk). Use should be restricted to trusted local inputs, with the message content treated as highly sensitive and not logged or shared.

Confidence: 64%Severity: 55%
AnomalyLOW
scripts/mail-send.sh

No direct indicators of hidden malware (e.g., obfuscation, backdoors, or credential/data theft) are present. However, the script executes AppleScript and performs a real ‘send email’ action, while embedding multiple untrusted inputs directly into AppleScript code with only partial escaping (double quotes in SUBJECT/BODY only) and with no sanitization for TO/FROM_ACCOUNT/ATTACHMENT. This creates a meaningful security risk of AppleScript/template manipulation and/or unwanted email sending and arbitrary file attachment when inputs are not fully trusted.

Confidence: 72%Severity: 52%
Audit Metadata
Analyzed At
Sep 25, 2026, 04:58 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fapple-mail%2F@fe8c9428c0a1ce0c3aa04aa991f28de7d6b1f0800b011d204a4cd8a3a593206c
Security Audit — socket — apple-mail