Back to skill

Security audit

IMAP Client

Security checks for vulnerabilities and agentic risk

Overview

This email-reading skill is mostly coherent, but its wrapper can expose mailbox credentials through unsafe argument forwarding and credential-file handling.

Install only if you are comfortable granting an agent access to the configured mailbox. Prefer OpenClaw SecretRef or short-lived environment injection over plaintext credential files, use a narrowly scoped app password, avoid shared or monitored machines, and do not allow user-supplied myl connection/authentication flags until the wrapper validates or rejects them. Pin or review the myl dependency before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/imap.sh:88
Finding

Unrestricted forwarded arguments can override trusted IMAP connection settings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/imap.sh:26
Finding

Credential file is executed as unrestricted shell code

Content
View full analysis
/dev/null || stat -f '%A' "$CRED_FILE" 2>/dev/null || echo "?") case "$perms" in 600|400) # shellcheck disable=SC1090 . "$CRED_FILE" ;; *) err "WARNING — $CRED_FILE has perms $perms (expected 600 or 400). Ignoring." err "Run: chmod 600 \"$CRED_FILE\"" ;; esac fi ``` ### Technical Analysis The wrapper uses the shell `.` command to load the credential file. Sourcing does not parse the file as passive configuration: it executes every shell expression in the file with the wrapper’s privileges and access to its environment. The permission check only accepts modes `600` and `400`, which reduces accidental disclosure but does not make the contents safe. The implementation does not explicitly verify: - That the file is owned by the current effective user. - That the path is not a symbolic link. - That parent directories cannot be replaced or manipulated. - That the file contains only the documented variables. - That assignments are literal and contain no command substitutions, functions, redirections, or other shell syntax. The environment-controlled `IMAP_CREDENTIALS_FILE` broadens the number of paths that may be sourced. ### Attack Path 1. An attacker gains control over the configured credential path or causes `IMAP_CREDENTIALS_FILE` to reference a crafted file. 2. The crafted file is assigned mode `600` or `400` and contains shell code, for example: ```bash IMAP_USER='use ...[truncated 960 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/imap.sh:127
Finding

IMAP password is exposed through process command-line metadata

Content
View full analysis
/dev/null 2>&1; then err "\`myl\` is not on PATH. See references/installation.md." exit 127 fi exec myl "${flags[@]}" "$@" ``` The exposure is also acknowledged in `SKILL.md:61-64`: ```text The wrapper reads credentials from env vars and passes them to `myl` via `--username`/`--password` flags. This means the password is briefly visible in `/proc//cmdline` and `ps` output to other processes on the same host while `myl` runs. ``` ### Technical Analysis Although the Agent-generated shell command does not contain the literal password, the wrapper expands `IMAP_PASSWORD` into `myl`’s argument vector. The secret can consequently appear in process inspection interfaces such as `/proc//cmdline`, process-monitoring tools, audit systems, crash diagnostics, or telemetry that records executable arguments. The wrapper protects shell history and conversation logs but does not provide end-to-end secret isolation. This is particularly risky on shared hosts, weakly isolated containers, or systems with monitoring agents that collect command lines. ### Attack Path 1. A legitimate mailbox operation starts `myl`. 2. The wrapper places the genuine password after the `--password` option in the process argument vector. 3. While the process is running, another process or monitoring component reads command-line metadata. 4. The observer extracts the password. 5. The captured app password is reused directly against the mailbox provider. The exact ability of an unrelated local account to inspect the process depends on operating-system protections such as `/proc` mount options, UID isolation, ptrace restrictions, and monitoring privileg ...[truncated 389 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/installation.md:47
Finding

Security-sensitive third-party mail client is installed from mutable, unpinned sources

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/troubleshooting.md:148
Finding

Manual OpenSSL troubleshooting procedure can expose the mailbox password

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/installation.md (reported line 47)May include surrounding context.

bash
# Install pipx itself if missing (Debian/Ubuntu)
sudo apt update && sudo apt install -y pipx
pipx ensurepath

# Install myl

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/installation.md (reported line 73)May include surrounding context.

ll myl

text

On macOS:

```bash
brew install pipx
pipx ensurepath
pipx install myl

After pipx ensurepath, the user may need to restart their shell or source ~/.bashrc / source ~/.zshrc for myl to appear on PATH.

pip --user — fallback when pipx isn't available

bash
pip install --user myl

The binary lands in ~/.local/bin, which must be on PATH. If not:

bash
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc

Nix flake — for Nix users

bash
# One-shot run without installing
nix run github:pschmitt/myl -- --help

# Or add to a flake

From source

bash
git clone https://github.com/pschmitt/myl.git
cd myl
pipx install .

Sandboxed agent runs

If the agent runs inside a Docker sandbox (OpenClaw agents.defaults.sandbox.docker), myl must be installed inside the container as well — the host bin doesn't satisfy the in-sandbox requirement. Add to setupCommand:

json
{
  "agents": {
    "defaults": {

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/troubleshooting.md (reported line 29)May include surrounding context.

t — file a bug against OpenClaw with metadata.openclaw excerpt + your skills.entries config (passwords redacted).

myl: command not found (non-OpenClaw)

OpenClaw shouldn't load this skill without myl because of requires.bins: ["myl"]. If you see this on Claude Code or another runtime:

  1. Installed via pip install --user but ~/.local/bin is not in PATH. Add it:
    bash
    echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc && source ~/.bashrc
    
  2. Installed via pipx but pipx ensurepath was never run, or the shell wasn't restarted.
  3. Installed in a virtualenv that isn't currently activated.
  4. Not actually installed. pip show myl or pipx list to confirm.

AUTHENTICATIONFAILED / Invalid credentials / LOGIN failed

The username + password combination was rejected. In order of likelihood:

  1. Wrong credential type. For Gmail, Yandex, Mail.ru, iCloud, Fastmail, Yahoo — the user must use an app-specific password, not the account

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The README recommends persisting IMAP credentials, including the password, in a local plaintext file under ~/.config/imap-client/credentials. Even with 600 permissions, this creates a durable secret on disk that can be exposed through local compromise, backups, endpoint telemetry, accidental inclusion in support bundles, or other user-context malware. In this skill's context, handling real mailbox credentials makes persistence more sensitive because compromise grants direct access to private email and attachments.

Content

Scanner excerpt · README.md (reported line 107)May include surrounding context.

export IMAP_PROVIDER='yandex'

text

**Headless / cron / fallback** — create `~/.config/imap-client/credentials`:

```bash
mkdir -p ~/.config/imap-client

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to execute shell commands (bash {baseDir}/scripts/check_myl.sh and bash {baseDir}/scripts/imap.sh) but does not declare any tool scope such as permissions or allowed-tools. In an agent runtime, missing scope boundaries can allow unintended shell access or make the skill runnable in environments where command execution policy is not clearly constrained, increasing the blast radius if the skill or its referenced scripts are modified or abused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is very broad and includes generic phrases like 'check my email', 'find the email from Y', and even provider names, which can cause the skill to activate for loosely related requests. Because this skill handles mailbox access and credential-dependent shell operations, accidental invocation could prompt unnecessary credential setup, unexpected mailbox queries, or disclosure of email metadata beyond the user's precise intent.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/authentication.md (reported line 36)May include surrounding context.

Then restart the agent session (or wait for the skills watcher to pick it up if skills.load.watch is enabled). The next time the agent runs the skill, IMAP_USER and IMAP_PASSWORD are already in the environment.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/troubleshooting.md (reported line 123)May include surrounding context.

Then restart the agent session (or wait for the skills watcher to pick it up if skills.load.watch is enabled). The next time the agent runs the skill, IMAP_USER and IMAP_PASSWORD are already in the environment.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 94)May include surrounding context.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Use apiKey with a SecretRef for stronger isolation. OpenClaw supports pulling the password from a separate source rather than inlining it as plaintext in the JSON:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 116)May include surrounding context.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Use apiKey with a SecretRef for stronger isolation. OpenClaw supports pulling the password from a separate source rather than inlining it as plaintext in the JSON:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/authentication.md (reported line 39)May include surrounding context.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Use apiKey with a SecretRef for stronger isolation. OpenClaw supports pulling the password from a separate source rather than inlining it as plaintext in the JSON:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/authentication.md (reported line 86)May include surrounding context.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Use apiKey with a SecretRef for stronger isolation. OpenClaw supports pulling the password from a separate source rather than inlining it as plaintext in the JSON:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 117)May include surrounding context.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Use apiKey with a SecretRef for stronger isolation. OpenClaw supports pulling the password from a separate source rather than inlining it as plaintext in the JSON:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 120)May include surrounding context.

Permissions matter. ~/.openclaw/openclaw.json should not be world-readable:

bash
chmod 600 ~/.openclaw/openclaw.json

Use apiKey with a SecretRef for stronger isolation. OpenClaw supports pulling the password from a separate source rather than inlining it as plaintext in the JSON:

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The skill explicitly documents storing IMAP credentials in a persistent plaintext file under ~/.config/imap-client/credentials. Even with mode 600, this creates a durable secret at rest that can be harvested by local malware, backups, accidental syncing, or other post-compromise access. In this skill context, the risk is meaningful because the stored secret grants ongoing mailbox access, which is highly sensitive.

Content

Scanner excerpt · references/authentication.md (reported line 80)May include surrounding context.

When neither Method A nor B is convenient (e.g. cron jobs, headless workflows, CI), drop a credentials file at ~/.config/imap-client/credentials:

bash
mkdir -p ~/.config/imap-client
cat > ~/.config/imap-client/credentials <<'EOF'
IMAP_USER='you@example.com'
IMAP_PASSWORD='app-specific-password-here'

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/authentication.md (reported line 89)May include surrounding context.

chmod 600 ~/.config/imap-client/credentials

text

The wrapper sources this file when `IMAP_USER`/`IMAP_PASSWORD` are not in the env, **but only if permissions are 600 or 400**. World-readable creds files are ignored with a warning.

To use a different path, set `IMAP_CREDENTIALS_FILE` in env.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation.md (reported line 47)May include surrounding context.

bash
# Install pipx itself if missing (Debian/Ubuntu)
sudo apt update && sudo apt install -y pipx
pipx ensurepath

# Install myl

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly presents a ## Marking as seen command and notes that it mutates server state. Later, the same file states that myl is read-only, which contradicts the documented behavior because marking messages seen changes mailbox state on the server.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 117)May include surrounding context.

Wrapper says perms warning, ignores creds file

The wrapper refuses to source ~/.config/imap-client/credentials (or $IMAP_CREDENTIALS_FILE) unless it's chmod 600 or chmod 400. Fix:

bash
chmod 600 ~/.config/imap-client/credentials

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The troubleshooting guide recommends enabling shell tracing (set -x) around execution of the IMAP wrapper. Shell tracing can echo expanded commands, arguments, and sourced values into terminal logs or session transcripts; in an email/IMAP skill, that creates a realistic risk of exposing usernames, passwords, or other sensitive environment-derived configuration during debugging.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 153)May include surrounding context.

md
# Lookup order for credentials:
#   1. Process env vars (set by OpenClaw skills.entries.imap-client.env, or
#      manually via `export` in the user's shell).
#   2. ~/.config/imap-client/credentials  (must be chmod 600 or 400).
#   3. $IMAP_CREDENTIALS_FILE             (override path; same perms required).
#
# Variables consumed:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/imap.sh (reported line 7)May include surrounding context.

sh
# Lookup order for credentials:
#   1. Process env vars (set by OpenClaw skills.entries.imap-client.env, or
#      manually via `export` in the user's shell).
#   2. ~/.config/imap-client/credentials  (must be chmod 600 or 400).
#   3. $IMAP_CREDENTIALS_FILE             (override path; same perms required).
#
# Variables consumed:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/imap.sh (reported line 39)May include surrounding context.

sh
# Lookup order for credentials:
#   1. Process env vars (set by OpenClaw skills.entries.imap-client.env, or
#      manually via `export` in the user's shell).
#   2. ~/.config/imap-client/credentials  (must be chmod 600 or 400).
#   3. $IMAP_CREDENTIALS_FILE             (override path; same perms required).
#
# Variables consumed:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/imap.sh (reported line 75)May include surrounding context.

sh
# Lookup order for credentials:
#   1. Process env vars (set by OpenClaw skills.entries.imap-client.env, or
#      manually via `export` in the user's shell).
#   2. ~/.config/imap-client/credentials  (must be chmod 600 or 400).
#   3. $IMAP_CREDENTIALS_FILE             (override path; same perms required).
#
# Variables consumed:

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
88% confidence
Finding

The script sources a credentials file from a path that can be overridden by IMAP_CREDENTIALS_FILE, but it validates only the mode bits and not ownership, symlink status, or whether the path is a regular file. If an attacker can influence that environment variable or the referenced filesystem path, they may cause arbitrary shell code execution when the file is sourced, because '.' executes file contents as Bash code rather than parsing a data-only format. In a skill that handles mailbox credentials, this is more dangerous because compromise can expose both local execution context and email secrets.

Content

Scanner excerpt · scripts/imap.sh (reported line 29)May include surrounding context.

sh
CRED_FILE="${IMAP_CREDENTIALS_FILE:-$HOME/.config/imap-client/credentials}"

if [[ ( -z "${IMAP_USER:-}" || -z "${IMAP_PASSWORD:-}" ) && -f "$CRED_FILE" ]]; then
  # Refuse to source a world-readable creds file. Permissions check works on
  # both GNU stat (Linux) and BSD stat (macOS).
  perms=$(stat -c '%a' "$CRED_FILE" 2>/dev/null || stat -f '%A' "$CRED_FILE" 2>/dev/null || echo "?")
  case "$perms" in

Static analysis

No suspicious patterns detected.