cold-email

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This skill is a coherent cold-email writing helper with no evidence of credential use, exfiltration, persistence, or automatic sending, though users should avoid deceptive outreach tactics and protect any local marketing context they provide.

This appears safe to install as a writing-assistance skill. Before using it, make sure any local marketing context file is appropriate to share with the agent, and review generated emails for truthful personalization, lawful unsubscribe handling, and non-misleading subject lines.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI09: Human-Agent Trust Exploitation
Low
What this means

If used carelessly, generated outreach could mislead recipients or create compliance and reputation risk for the sender.

Why it was flagged

The skill is explicitly for cold outreach, and this subject-line guidance could be used in a way that makes a message seem more familiar or relationship-based than it really is.

Skill content
The Shared Context
Implies a pre-existing relationship or shared frame.
- `re: EMEA expansion`
- `following up on the hiring spike`
Recommendation

Use only truthful subject lines and personalization; do not imply a prior relationship, referral, or thread unless it is real, and follow applicable email laws.

#
ASI06: Memory and Context Poisoning
Low
What this means

Information in the local marketing context could influence generated emails and may be reused in outreach drafts.

Why it was flagged

The skill may use a local persistent context file to shape generated outreach. This is limited and purpose-aligned, but the file could contain sensitive business details or outdated instructions.

Skill content
If `marketing-context.md` exists, read it before asking questions.
Recommendation

Review marketing-context.md before use, avoid putting secrets or private prospect data in it, and keep its instructions current.