T09 · Insecure Skill Coding Practices
- Location
scripts/agentmail-send.py:102- Finding
SMTP Authentication Can Occur Without Transport Encryption
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This email automation skill is mostly transparent about its purpose, but it gives an agent recurring access to private email, outbound sending, and local file attachments without enough scoping or approval controls.
Review this skill carefully before installing. Use a dedicated low-privilege email account or revocable app password, keep credential files locked down, avoid autonomous replies by default, require confirmation before sending any email or attachment, and restrict file searches to explicit safe directories.
scripts/agentmail-send.py:102SMTP Authentication Can Occur Without Transport Encryption
scripts/find-zip-email.py:67Predictable Temporary ZIP Path Permits Symlink and File-Collision Attacks
README.md:84Email Credentials Are Stored in Plaintext Files Without Enforced Access Controls
report.md:265Untrusted Email Content Is Fed Into an Autonomous Agent Workflow Without an Authorization Boundary
The documented workflow allows email content to drive local file discovery, zipping, and outbound transmission, but the README does not prominently warn that this can disclose arbitrary local files if prompts, patterns, or directories are too broad. Because email is untrusted input, this creates a realistic exfiltration path from inbox messages to local filesystem data.
The documentation instructs users to copy credentials into a local .env under the agent workspace, which may be accessible to the agent, backups, logs, or other tooling in that workspace. In a skill that reads and sends email, exposure of SMTP or API credentials enables account abuse, impersonation, and further data access.
# Copy the example env file
cp SolEmail/.env.example ~/.openclaw/workspace/.env
# Edit it with your actual credentials
nano ~/.openclaw/workspace/.env
The follow-on instructions to edit the workspace .env with real credentials reinforce a pattern of placing live secrets in an agent-controlled area. Given this skill's purpose, compromise of those credentials can directly enable unauthorized outbound email, inbox access, or abuse of webhook-based mail integrations.
cp SolEmail/.env.example ~/.openclaw/workspace/.env
nano ~/.openclaw/workspace/.env
### 5. Test sending
The declared description suggests a broader email skill that can both read and send emails through SolEmail, including reply and automation workflows. The provided code chunk is narrowly scoped to inbox access: it invokes the himalaya CLI to list envelopes and read message bodies from a local Maildir-style store. There is no implementation for composing, sending, replying, handling attachments for outbound mail, or creating automation rules. Additionally, the underlying resource/system differs from the declaration: the code operates on a local Himalaya mail store rather than a SolEmail automation system. This is a material description-behavior mismatch, not just an implementation detail.
The description overstates the skill’s functionality. The code chunk is a focused SMTP sender: it constructs a plain-text email, optionally attaches files, authenticates to an SMTP server, and sends the message. There is no code for reading inbox contents, fetching messages, threading/reply logic, or automation setup. Additionally, the declared description refers to the SolEmail automation system, but the implementation uses generic SMTP (defaulting to iCloud SMTP) and environment variables, which is materially different from the named system. Sending files by email is supported, but the broader declared purpose is not accurately represented by this code.
The documented workflow to find files, zip them, and email them creates a direct bulk-exfiltration path from local storage to an external recipient. Without an explicit warning, path restrictions, or confirmation safeguards, a user or agent could unintentionally package and transmit large sets of sensitive documents from directories like Downloads.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
["himalaya"] + args,
capture_output=True,
text=True,
env={**os.environ, "HIMALAYA_CONFIG_PATH": HIMALAYA_CONFIG_PATH}
)
if result.returncode != 0:
print(f"himalaya error: {result.stderr}", file=sys.stderr)
The README explicitly promotes fully automated email reading and replying without emphasizing human approval or outbound-action safeguards. In an agent skill context, autonomous replies can send incorrect, sensitive, or reputation-damaging messages on the user's behalf, especially when triggered by untrusted email content.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
brew install himalaya
sudo pacman -S himalaya
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Copy the config template:
mkdir -p ~/.config/himalaya
cp SolEmail/config/himalaya/config.toml ~/.config/himalaya/config.toml
nano ~/.config/himalaya/config.toml
# Fill in: host, port, username, app-specific password
The README recommends persistent scheduled execution via cron, causing the email-processing capability to run automatically and repeatedly without per-run user intent. In combination with autonomous reading/replying and file-emailing features, persistence increases the blast radius of misconfiguration, prompt injection via email, or credential misuse.
Run automated email checks on a schedule. Add to your crontab (crontab -e):
# Check email every 15 minutes, log to file
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Create ~/.openclaw/workspace/skills/sol-email/SKILL.md:
---
name: sol-email
The skill documents shell execution, filesystem access, and use of environment-stored SMTP credentials, but it declares no explicit tool scope or permission boundaries. In an agent setting, this increases the chance the skill can be invoked with broader-than-necessary access, enabling unintended email sending, mailbox access, or file exfiltration through attachments.
The activation language is broad enough to match many ordinary email-related requests, which can cause the agent to invoke a powerful email skill too readily. Because this skill can read inbox contents, send external messages, and attach local files, overbroad triggering raises the risk of privacy violations and unauthorized outbound data transfer.
The skill handles highly sensitive data—private email content, contacts, attachments, and SMTP credentials—yet it provides no clear privacy or external-transmission warning. Users or downstream agents may underestimate that reading email exposes personal data and that sending email can disclose local files or confidential content to external recipients.
The report explicitly describes granting an AI autonomous access to a human's personal email account, including reading, filtering, and responding without routine human involvement, but it does not pair that capability with strong warnings, approval gates, or constrained response policies. In this skill context, email is a high-impact channel containing sensitive data and the ability to impersonate the user, so omission of explicit safety guardrails materially increases privacy, fraud, and account-abuse risk.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
himalaya read -- 42
himalaya write
The `-w 200` flag sets output width to 200 characters, which affects how the envelope table formats dates and subjects. Pipe-delimited output makes parsing easy in Python.
The scheduled cron workflow runs recurring autonomous inbox checks and may respond every 15 minutes, yet the documentation does not require confirmation before sending or warn about accidental, repeated, or policy-violating actions. In an email automation skill, recurrence amplifies mistakes: one bad prompt interpretation, malicious email, or logic bug can repeatedly leak information, spam contacts, or take actions before a human notices.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_himalaya(args: list) -> str:
"""Run himalaya CLI and return output."""
result = subprocess.run(
["himalaya"] + args,
capture_output=True,
text=True,
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
def run_himalaya(args: list) -> str:
"""Run himalaya CLI and return output."""
result = subprocess.run(
["himalaya"] + args,
capture_output=True,
text=True,
This script prints email metadata and full message bodies directly to stdout or JSON, which can expose sensitive personal or business information to logs, calling agents, terminal history, or downstream tooling. In an automation skill specifically designed to read email, that data exposure is contextually more dangerous because emails commonly contain credentials, links, attachments, and private content.
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
**Credentials in environment variables:** No passwords in scripts, no passwords in config files in the repo. The `.env` file is explicitly not committed to git (it's in `.gitignore` in the workspace).
**Local Maildir permissions:** The `~/.mail/` directory should be set to `600` or `700` so only the owner can read it.
**No script evaluation from email content:** The AI agent reads email content and decides what to do. We deliberately do not have any mechanism that auto-evaluates email content as code or command. The AI is an intermediary, not a code execution engine.
This code accesses sensitive environment variables, including SMTP_USER and SMTP_PASSWORD, to authenticate outbound email. Although the module docstring documents the variables technically, there is no runtime disclosure or explicit warning to the user that credentials will be read and used for network transmission.
Detected: suspicious.exposed_secret_literal