ClawEmail Admin

Security checks across malware telemetry and agentic risk

Overview

This is a clear ClawEmail administration skill, but it gives an agent authority to permanently delete email accounts and their data without documented confirmation safeguards.

Review before installing. Use only an API key you are comfortable giving to an agent, treat returned passwords and OAuth connection details as secrets, and require a manual confirmation step before suspend or delete actions, especially permanent deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents a permanent delete operation for Google Workspace accounts and associated data without requiring or even recommending confirmation, scope validation, or user acknowledgement. In an agent-executed context, this increases the risk of accidental irreversible destruction of accounts and data due to misunderstanding, prompt injection, or mistaken identity of the target prefix.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal