Qq Mail

PassAudited by VirusTotal on May 11, 2026.

Overview

Type: OpenClaw Skill Name: qq-mail Version: 0.1.0 The skill bundle consists only of metadata and a documentation file (SKILL.md) providing guidelines for an AI agent to interact with QQ Mail. It contains no executable code and explicitly instructs the agent to avoid sensitive actions such as login automation, message sending, or storing email content, focusing instead on non-sensitive metadata summaries.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may see and summarize who emailed the user, subject lines, timestamps, labels, unread status, and related links.

Why it was flagged

The skill is intended to read metadata from logged-in QQ Mail views. This is purpose-aligned, but it involves account-specific mailbox information.

Skill content
邮件列表的主题/发件人/时间摘要(仅在登录与可视范围内)
Recommendation

Use it only with your own QQ Mail account, limit the folders or links you ask it to inspect, and avoid using it on highly sensitive messages.

What this means

A user might underestimate the privacy implications of sharing mailbox metadata with an agent.

Why it was flagged

The skill frames the data as non-sensitive, while the disclosed fields include email subjects, senders, times, labels, and source links, which many users may consider private.

Skill content
面向公开分享页面与个人邮箱中可视的非敏感信息摘要
Recommendation

Treat email metadata as private even when the skill avoids message bodies and attachments.