Back to skill

Security audit

Inbox Triage

Security checks for vulnerabilities and agentic risk

Overview

This email triage skill is useful and mostly coherent, but it handles sensitive inbox contents and suggests external notifications, mailbox archiving, and persistent profiling without enough scoping or disclosure.

Review before installing. Use read-only, unread-only, and headers-only defaults where possible; require explicit confirmation before scans, live archiving, reply sending, or external notifications; disable Telegram, backup-contact escalation, and memory profiling unless you have a clear need and trusted destinations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:121
Finding

Email-Derived Sensitive Information May Be Disclosed Through External Messaging Channels

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34-35, SKILL.md:121, SKILL.md:159, SKILL.md:240, and references/advanced-patterns.md:103-107
Vulnerability Type: Sensitive information exposure through externally delivered reports
Risk Level: Medium

Evidence

SKILL.md:34-35:

markdown
For each email, the report includes: sender, subject, one-line summary, and recommended action.

SKILL.md:121:

text
openclaw cron add --schedule "0 8,12,17 * * 1-5" --task "Run inbox triage, deliver report to main chat"

SKILL.md:159:

markdown
Adjust verbosity based on channel. Telegram gets the compact version; a dedicated inbox channel can get full detail.

SKILL.md:240:

markdown
- This skill processes email content locally — nothing leaves your machine

references/advanced-patterns.md:103-107:

markdown
## Escalation Rules
- 🔴 Urgent + no human response in 30 min → send reminder via Telegram
- 🔴 Urgent + no response in 2h → send to backup contact
- 🟡 Action Needed + no response in 24h → bump to next triage with ⚠️

Technical Analysis

The Skill reads email headers and bodies and creates reports containing sender identities, subjects, summaries, and recommended actions. These fields can contain confidential personal, commercial, legal, or authentication-related information.

The scheduled reporting and escalation instructions permit this email-derived information to be delivered to a main chat, Telegram, or an unspecified backup contact. The Skill does not require recipient allowlisting, destination validation, field-level redaction, transport verification, or human approval before escalation. The behavior also contradicts the unconditional privacy statement that nothing leaves the machine.

Reading email content is necessary for semantic triage. Transmitting summaries and metadata to third-party messaging services or backup contacts is no ...[truncated 1602 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make all external delivery disabled by default and require explicit, informed opt-in for each destination.
  2. Default to displaying reports only in a trusted local session.
  3. Maintain an explicit allowlist of approved account IDs, chat IDs, and recipients; do not accept free-form backup contacts.
  4. Require human approval before sending any email-derived information to a backup contact.
  5. Minimize external notifications to a generic alert and an opaque local message identifier. Exclude senders, subjects, body summaries, attachments, and quoted text by default.
  6. Add configurable redaction for personal data, credentials, financial details, legal content, and security tokens.
  7. Verify that destination channels use appropriate access controls and encrypted transport.
  8. Separate local triage from external notification permissions so enabling inbox access does not implicitly authorize network transmission.
  9. Record an auditable local log of the destination and fields disclosed without duplicating sensitive message content.
  10. Replace the statement that nothing leaves the machine with an accurate data-flow disclosure explaining that configured chat and escalation integrations may transmit email-derived information.

T09 · Insecure Skill Coding Practices

Note
Location
references/advanced-patterns.md:77
Finding

Sensitive Correspondence Metadata May Be Persisted Without Retention or Access Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:233 and references/advanced-patterns.md:19-25,77-96
Vulnerability Type: Insecure persistence of sensitive email metadata
Risk Level: Low

Evidence

SKILL.md:233:

markdown
- **Memory Architect:** Log important emails to daily memory notes

references/advanced-patterns.md:19-25:

markdown
## Thread Tracking

Track ongoing email threads that need follow-up:

```markdown
## Active Threads (in daily memory notes)
- **[Client Name] — Contract Review** | Waiting on their reply since Mon | Follow up Wed if silent
- **[Vendor] — Invoice Dispute** | Sent clarification Tue | Escalate if no response by Fri
text

`references/advanced-patterns.md:77-96`:

```markdown
## Sender Intelligence

Build a sender profile over time:

```json
{
  "sender_profiles": {
    "boss@company.com": {
      "avg_response_expected": "2h",
      "typical_urgency": "high",
      "usual_topics": ["project updates", "meeting requests"],
      "reply_rate": 0.95
    },
    "newsletter@techcrunch.com": {
      "avg_response_expected": null,
      "typical_urgency": "noise",
      "reply_rate": 0.0
    }
  }
}

Update profiles weekly. After a month, the agent knows your inbox better than you do.

text

### Technical Analysis

The optional thread-tracking and sender-intelligence features create durable records of correspondent identities, business relationships, discussion topics, response expectations, and dispute or contract status. The instructions do not define a retention period, deletion procedure, storage location, encryption requirement, file permissions, synchronization policy, or access boundary.

Persistent metadata may remain accessible after the original email is deleted or after the triage session ends. Daily memory files and sender profiles may also be copied into backups, synchronized workspaces, version-control r
...[truncated 1579 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make persistent thread tracking and sender profiling explicitly opt-in.
  2. Store opaque message or thread identifiers and minimal state fields instead of names, addresses, subjects, or body-derived topics.
  3. Define short retention periods and automatically remove closed threads and stale profiles.
  4. Provide a documented command or process to inspect and delete all retained inbox metadata.
  5. Store sensitive state in an access-controlled location with restrictive file permissions and encryption at rest where available.
  6. Exclude memory and profile files from version control, shared workspaces, telemetry, and cloud synchronization by default.
  7. Avoid recording contracts, disputes, financial matters, health information, credentials, or other sensitive body-derived details.
  8. Partition stored state by email account and user so one account or agent session cannot read another account's profiles.
  9. Inform users precisely which fields are retained, where they are stored, and how long they remain.
  10. Periodically review and purge accumulated profiles to prevent an unnecessarily broad behavioral history.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The introductory description emphasizes convenience and automatic inbox triage but does not prominently foreground that the agent will read potentially sensitive email subjects and bodies. This increases the risk that users enable the skill without fully understanding the privacy implications, leading to overbroad access to confidential personal, business, financial, or legal communications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The suggested on-demand triggers, such as asking the agent to 'Check my email' or 'What's in my inbox?', are broad natural-language phrases that can easily arise in ordinary conversation. In an agent environment with automatic skill routing, this can cause unintended inbox access and summarization of sensitive email content without a deliberate, high-confidence user invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The auto-archiving section recommends mailbox-modifying commands and operational rollout guidance, but it does not explicitly warn that these actions change mailbox state and may archive legitimate messages if classification is wrong. In an AI-agent skill, that omission matters because an automated agent may treat the examples as directly actionable, increasing the chance of unintended mail handling and missed important emails.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.