Back to skill

Security audit

ClawEmail Admin

Security checks across malware telemetry and agentic risk

Overview

This is a clear ClawEmail admin skill, but it gives an agent power to permanently delete Google Workspace email accounts and data without documented confirmation safeguards.

Review before installing. Only use an API key you are comfortable giving to an agent, treat returned passwords and OAuth connection details as secrets, and require a manual confirmation step before destructive actions, especially permanent deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill exposes a permanent account deletion operation but does not require or even recommend an explicit confirmation or warning before invoking it. In an agent context, destructive actions are especially risky because a misinterpreted prompt, automation error, or prompt injection could trigger irreversible deletion of a Google Workspace account and its associated data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.