T09 · Insecure Skill Coding Practices
- Location
SKILL.md:121- Finding
Email-Derived Sensitive Information May Be Disclosed Through External Messaging Channels
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:34-35,SKILL.md:121,SKILL.md:159,SKILL.md:240, andreferences/advanced-patterns.md:103-107
Vulnerability Type: Sensitive information exposure through externally delivered reports
Risk Level: MediumEvidence
SKILL.md:34-35:markdown For each email, the report includes: sender, subject, one-line summary, and recommended action.SKILL.md:121:text openclaw cron add --schedule "0 8,12,17 * * 1-5" --task "Run inbox triage, deliver report to main chat"SKILL.md:159:markdown Adjust verbosity based on channel. Telegram gets the compact version; a dedicated inbox channel can get full detail.SKILL.md:240:markdown - This skill processes email content locally — nothing leaves your machinereferences/advanced-patterns.md:103-107:markdown ## Escalation Rules - 🔴 Urgent + no human response in 30 min → send reminder via Telegram - 🔴 Urgent + no response in 2h → send to backup contact - 🟡 Action Needed + no response in 24h → bump to next triage with ⚠️Technical Analysis
The Skill reads email headers and bodies and creates reports containing sender identities, subjects, summaries, and recommended actions. These fields can contain confidential personal, commercial, legal, or authentication-related information.
The scheduled reporting and escalation instructions permit this email-derived information to be delivered to a main chat, Telegram, or an unspecified backup contact. The Skill does not require recipient allowlisting, destination validation, field-level redaction, transport verification, or human approval before escalation. The behavior also contradicts the unconditional privacy statement that nothing leaves the machine.
Reading email content is necessary for semantic triage. Transmitting summaries and metadata to third-party messaging services or backup contacts is no ...[truncated 1602 chars]
- Remediation
View remediation
Remediation Suggestions
- Make all external delivery disabled by default and require explicit, informed opt-in for each destination.
- Default to displaying reports only in a trusted local session.
- Maintain an explicit allowlist of approved account IDs, chat IDs, and recipients; do not accept free-form backup contacts.
- Require human approval before sending any email-derived information to a backup contact.
- Minimize external notifications to a generic alert and an opaque local message identifier. Exclude senders, subjects, body summaries, attachments, and quoted text by default.
- Add configurable redaction for personal data, credentials, financial details, legal content, and security tokens.
- Verify that destination channels use appropriate access controls and encrypted transport.
- Separate local triage from external notification permissions so enabling inbox access does not implicitly authorize network transmission.
- Record an auditable local log of the destination and fields disclosed without duplicating sensitive message content.
- Replace the statement that nothing leaves the machine with an accurate data-flow disclosure explaining that configured chat and escalation integrations may transmit email-derived information.
