Back to skill

Security audit

ClawMail

Security checks across malware telemetry and agentic risk

Overview

ClawMail is a coherent email API skill, but it gives agents autonomous external email authority without clear approval or recipient-scope safeguards.

Install only if you intentionally want an agent to operate an email identity. Protect the ClawMail API key like a password, avoid storing it in general agent memory, review remote updates before applying them, and configure your agent or surrounding policy to require approval, recipient/domain limits, logging, and safe handling of untrusted inbound email before allowing autonomous sends.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises autonomous email sending/receiving and even states 'no human intervention required,' but the top-level description does not prominently warn that email contents, recipient addresses, and inbound messages may contain sensitive data or trigger external actions. In an agent ecosystem, this omission increases the chance that operators enable the skill without understanding privacy, impersonation, phishing, or unintended data exfiltration risks inherent to autonomous email handling.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.