Back to skill

Security audit

SolEmail

Security checks for vulnerabilities and agentic risk

Overview

This email automation skill is mostly transparent about its purpose, but it gives an agent recurring access to private email, outbound sending, and local file attachments without enough scoping or approval controls.

Review this skill carefully before installing. Use a dedicated low-privilege email account or revocable app password, keep credential files locked down, avoid autonomous replies by default, require confirmation before sending any email or attachment, and restrict file searches to explicit safe directories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agentmail-send.py:102
Finding

SMTP Authentication Can Occur Without Transport Encryption

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/find-zip-email.py:67
Finding

Predictable Temporary ZIP Path Permits Symlink and File-Collision Attacks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:84
Finding

Email Credentials Are Stored in Plaintext Files Without Enforced Access Controls

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
report.md:265
Finding

Untrusted Email Content Is Fed Into an Autonomous Agent Workflow Without an Authorization Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (23)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented workflow allows email content to drive local file discovery, zipping, and outbound transmission, but the README does not prominently warn that this can disclose arbitrary local files if prompts, patterns, or directories are too broad. Because email is untrusted input, this creates a realistic exfiltration path from inbox messages to local filesystem data.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The documentation instructs users to copy credentials into a local .env under the agent workspace, which may be accessible to the agent, backups, logs, or other tooling in that workspace. In a skill that reads and sends email, exposure of SMTP or API credentials enables account abuse, impersonation, and further data access.

Content

Scanner excerpt · README.md (reported line 111)May include surrounding context.

bash
# Copy the example env file
cp SolEmail/.env.example ~/.openclaw/workspace/.env

# Edit it with your actual credentials
nano ~/.openclaw/workspace/.env

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The follow-on instructions to edit the workspace .env with real credentials reinforce a pattern of placing live secrets in an agent-controlled area. Given this skill's purpose, compromise of those credentials can directly enable unauthorized outbound email, inbox access, or abuse of webhook-based mail integrations.

Content

Scanner excerpt · README.md (reported line 114)May include surrounding context.

cp SolEmail/.env.example ~/.openclaw/workspace/.env

Edit it with your actual credentials

nano ~/.openclaw/workspace/.env

text

### 5. Test sending

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description suggests a broader email skill that can both read and send emails through SolEmail, including reply and automation workflows. The provided code chunk is narrowly scoped to inbox access: it invokes the himalaya CLI to list envelopes and read message bodies from a local Maildir-style store. There is no implementation for composing, sending, replying, handling attachments for outbound mail, or creating automation rules. Additionally, the underlying resource/system differs from the declaration: the code operates on a local Himalaya mail store rather than a SolEmail automation system. This is a material description-behavior mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description overstates the skill’s functionality. The code chunk is a focused SMTP sender: it constructs a plain-text email, optionally attaches files, authenticates to an SMTP server, and sends the message. There is no code for reading inbox contents, fetching messages, threading/reply logic, or automation setup. Additionally, the declared description refers to the SolEmail automation system, but the implementation uses generic SMTP (defaulting to iCloud SMTP) and environment variables, which is materially different from the named system. Sending files by email is supported, but the broader declared purpose is not accurately represented by this code.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented workflow to find files, zip them, and email them creates a direct bulk-exfiltration path from local storage to an external recipient. Without an explicit warning, path restrictions, or confirmation safeguards, a user or agent could unintentionally package and transmit large sets of sensitive documents from directories like Downloads.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/agentmail-inbox.py (reported line 39)May include surrounding context.

python
["himalaya"] + args,
        capture_output=True,
        text=True,
        env={**os.environ, "HIMALAYA_CONFIG_PATH": HIMALAYA_CONFIG_PATH}
    )
    if result.returncode != 0:
        print(f"himalaya error: {result.stderr}", file=sys.stderr)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly promotes fully automated email reading and replying without emphasizing human approval or outbound-action safeguards. In an agent skill context, autonomous replies can send incorrect, sensitive, or reputation-damaging messages on the user's behalf, especially when triggered by untrusted email content.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 78)May include surrounding context.

brew install himalaya

Linux (Arch)

sudo pacman -S himalaya

Or build from source: https://github.com/soywod/himalaya#installation

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 87)May include surrounding context.

Copy the config template:

bash
mkdir -p ~/.config/himalaya
cp SolEmail/config/himalaya/config.toml ~/.config/himalaya/config.toml
nano ~/.config/himalaya/config.toml
# Fill in: host, port, username, app-specific password

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The README recommends persistent scheduled execution via cron, causing the email-processing capability to run automatically and repeatedly without per-run user intent. In combination with autonomous reading/replying and file-emailing features, persistence increases the blast radius of misconfiguration, prompt injection via email, or credential misuse.

Content

Scanner excerpt · README.md (reported line 244)May include surrounding context.

Cron Jobs

Run automated email checks on a schedule. Add to your crontab (crontab -e):

cron
# Check email every 15 minutes, log to file

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 310)May include surrounding context.

Adding to OpenClaw as a skill

Create ~/.openclaw/workspace/skills/sol-email/SKILL.md:

markdown
---
name: sol-email

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell execution, filesystem access, and use of environment-stored SMTP credentials, but it declares no explicit tool scope or permission boundaries. In an agent setting, this increases the chance the skill can be invoked with broader-than-necessary access, enabling unintended email sending, mailbox access, or file exfiltration through attachments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation language is broad enough to match many ordinary email-related requests, which can cause the agent to invoke a powerful email skill too readily. Because this skill can read inbox contents, send external messages, and attach local files, overbroad triggering raises the risk of privacy violations and unauthorized outbound data transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill handles highly sensitive data—private email content, contacts, attachments, and SMTP credentials—yet it provides no clear privacy or external-transmission warning. Users or downstream agents may underestimate that reading email exposes personal data and that sending email can disclose local files or confidential content to external recipients.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report explicitly describes granting an AI autonomous access to a human's personal email account, including reading, filtering, and responding without routine human involvement, but it does not pair that capability with strong warnings, approval gates, or constrained response policies. In this skill context, email is a high-impact channel containing sensitive data and the ability to impersonate the user, so omission of explicit safety guardrails materially increases privacy, fraud, and account-abuse risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · report.md (reported line 159)May include surrounding context.

himalaya read -- 42

Send an email (composes in $EDITOR)

himalaya write

text

The `-w 200` flag sets output width to 200 characters, which affects how the envelope table formats dates and subjects. Pipe-delimited output makes parsing easy in Python.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The scheduled cron workflow runs recurring autonomous inbox checks and may respond every 15 minutes, yet the documentation does not require confirmation before sending or warn about accidental, repeated, or policy-violating actions. In an email automation skill, recurrence amplifies mistakes: one bad prompt interpretation, malicious email, or logic bug can repeatedly leak information, spam contacts, or take actions before a human notices.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/agentmail-inbox.py (reported line 35)May include surrounding context.

python
def run_himalaya(args: list) -> str:
    """Run himalaya CLI and return output."""
    result = subprocess.run(
        ["himalaya"] + args,
        capture_output=True,
        text=True,

Tainted flow: 'HIMALAYA_CONFIG_PATH' from os.environ.get (line 27, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/agentmail-inbox.py (reported line 35)May include surrounding context.

python
def run_himalaya(args: list) -> str:
    """Run himalaya CLI and return output."""
    result = subprocess.run(
        ["himalaya"] + args,
        capture_output=True,
        text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This script prints email metadata and full message bodies directly to stdout or JSON, which can expose sensitive personal or business information to logs, calling agents, terminal history, or downstream tooling. In an automation skill specifically designed to read email, that data exposure is contextually more dangerous because emails commonly contain credentials, links, attachments, and private content.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · report.md (reported line 243)May include surrounding context.

md
**Credentials in environment variables:** No passwords in scripts, no passwords in config files in the repo. The `.env` file is explicitly not committed to git (it's in `.gitignore` in the workspace).

**Local Maildir permissions:** The `~/.mail/` directory should be set to `600` or `700` so only the owner can read it.

**No script evaluation from email content:** The AI agent reads email content and decides what to do. We deliberately do not have any mechanism that auto-evaluates email content as code or command. The AI is an intermediary, not a code execution engine.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code accesses sensitive environment variables, including SMTP_USER and SMTP_PASSWORD, to authenticate outbound email. Although the module docstring documents the variables technically, there is no runtime disclosure or explicit warning to the user that credentials will be read and used for network transmission.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
config/himalaya/config.toml:29

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
report.md:131

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:94