Back to skill

Security audit

ClawEmail Admin

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-built for ClawEmail account administration, but it needs review because it can permanently delete Google Workspace accounts without documented confirmation safeguards.

Install only if you trust the ClawEmail service and intend to let an agent administer these accounts. Keep CLAWEMAIL_API_KEY, generated passwords, and OAuth credentials private, and require manual confirmation of the exact email prefix before any suspend or delete action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill includes a permanent delete operation for Google Workspace accounts and associated data, but it does not instruct the agent to obtain explicit confirmation, warn about irreversibility, or verify the target account before issuing the request. In an agentic context, this increases the risk of accidental or prompt-induced destructive actions that cannot be undone.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.