Caveat verdict
ymailink
Terminal email client supporting IMAP/SMTP/Outlook/Gmail/Exchange with user-configured credentials; consistent with stated email management purpose and no exfiltration evident.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (2)
Possible hardcoded credential
references/configuration.md · code · secret = "optional-for-native-apps
Instruction-prose smuggling shape detected: collects a sensitive target ("passwords") and emits it outward ("forward"). Phrased as prose with no trigger tokens — a semantic prompt-injection / data-exfil pattern the syntactic scanners can't see. Final tier capped at Caution; review the instructions before installing.
SKILL.md · - **Message IDs are folder-scoped** (IMAP UIDs). Re-list after changing folders. - **Plural aliases** work for all command groups: `accounts`, `folders`, `flags
Permissions & capabilities
Requires 1 system binary.
package_install Is this flag fair?
Thanks — recorded.