T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:11- Finding
Use of an Overprivileged Supabase Service-Role Credential
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This lead-management skill matches its stated purpose, but it asks for a powerful Supabase service-role key and has tenant-scoping gaps around sensitive CRM data.
Review carefully before installing. Use a narrowly scoped Supabase credential or backend RPC/API instead of a broad service-role key, add explicit consent before capturing contact details or sending auto-replies, define retention/redaction rules for conversation logs, and confirm tenant filters protect every read, update, and delete path.
SKILL.md:11Use of an Overprivileged Supabase Service-Role Credential
src/api.ts:242Missing Tenant Constraint in Privileged Lead Queries
README.md:15Unpinned Package Execution Through npx Installation Command
The skill is explicitly designed to capture leads, store them in Supabase, and trigger automated email workflows, but the README does not prominently warn that user conversation content and contact details may be transmitted to third-party systems. In a lead-management context, this omission increases the chance of collecting or forwarding personal data without adequate notice, consent, or minimization.
The README instructs users to execute npx clawdhub install lead-inbox-automator without pinning a specific version. This creates a supply-chain risk because future or compromised package releases could be fetched and executed implicitly, especially dangerous in an installation path that users are likely to copy-paste directly.
The README recommends logging all agent replies with addConversation(), which encourages retaining full conversation content in persistent storage. In this skill's context, those messages may contain personal data, sensitive requests, or regulated business information, increasing exposure in the event of overcollection, unauthorized access, or later misuse.
The skill explicitly captures lead contact data, stores it in Supabase, and triggers Make.com email automation, but the description does not clearly warn users that personal data will be transmitted to external services and that an automated outbound email will be sent. This creates a meaningful privacy and consent risk, especially because agents may invoke createLead in the background based on conversational context without the end user understanding that their email, name, phone, and message metadata are being shared and acted upon.
This manifest description describes general lead inbox automation behavior but does not specify narrow activation conditions, trigger phrases, or exclusion boundaries. For a manifest file, this can make invocation scope ambiguous and increase the chance of unintended activation in contexts involving generic lead or inbox tasks.
The deleteLead method deletes records from the leads table, which is an irreversible data-affecting operation. Although the docstring says "use with caution," the code itself provides no confirmation prompt, user-facing warning, or safeguard before executing the deletion.
The file is primarily written in German, but the automation diagram includes the Chinese term "实时" with no justification or opt-in. This creates an unexplained locale inconsistency in user-facing documentation, which can violate language/locale policy expectations.
The runtime dependency uses a caret version range, which allows automatic installation of newer minor and patch releases. This can introduce supply-chain risk if an upstream release is compromised or contains a breaking security-relevant change, especially because this package likely handles CRM and inbox automation data.
"author": "Developer",
"license": "MIT",
"dependencies": {
"@supabase/supabase-js": "^2.39.0"
},
"devDependencies": {
"typescript": "^5.3.0"
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"@supabase/supabase-js": "^2.39.0"
},
"devDependencies": {
"typescript": "^5.3.0"
}
}
The description says the email is used for "auto-reply," which suggests user-facing generated communication, but the schema provides no indication that language or locale is user-selected or configurable. Because policy violations can appear in config text, this may reflect a default communication behavior that does not offer language choice.
This manifest-format JSON schema states that "automation triggers on 'new'" but does not explain what automation runs, when it does not run, or any limiting conditions. In a manifest-like file, this is an ambiguous activation description that could lead to unintended or overly broad downstream invocation behavior.
No suspicious patterns detected.