Back to skill

Security audit

Clawemail

Security checks for vulnerabilities and agentic risk

Overview

This Google Workspace skill is coherent and not clearly malicious, but it grants broad email, Drive, document, calendar, and form authority without enough user-control and secret-handling safeguards.

Install only if you are comfortable giving an agent broad Google Workspace access. Use a dedicated or least-privileged Google account if possible, restrict credential and cache file permissions, avoid shared machines, and require explicit confirmation before sending email, sharing or deleting Drive files, modifying documents or sheets, changing calendar events, or reading sensitive messages and files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:13
Finding

OAuth Credential File Setup Does Not Require Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/token.sh:7
Finding

Cached OAuth Access Token Is Written Without Enforced Owner-Only Permissions

Content
View full analysis
"$CACHE_FILE" echo -n "$ACCESS_TOKEN" ``` ### Technical Analysis The script stores an OAuth bearer token in a persistent plaintext cache file. It creates the cache directory with `mkdir -p` and writes the token with shell redirection, but it does not set a restrictive `umask`, explicitly create the directory with mode `0700`, or ensure that the token file has mode `0600`. The resulting permissions therefore depend on the invoking process's `umask` and any pre-existing cache directory or file. Under a permissive configuration, another local user may read the cached bearer token. If the cache file already exists with unsafe ownership or permissions, overwriting it does not correct those permissions. The cache is used for up to 50 minutes, so a stolen token may remain useful for the remainder of its OAuth lifetime. Because bearer tokens confer authority solely through possession, an attacker does not need the client secret or refresh token to use a stolen cached token. ### Attack Path 1. The victim executes `scripts/token.sh`. 2. The script refreshes an OAuth access token and writes it to the configured cache file. 3. The cache directory or token file has permissions that allow another local user or compromised process to read it. 4. The attacker copies the plaintext access token from the cache. 5. The attacker supplies the token in an `Authorization: Bearer` header to an authorized Google API. 6. The attacker acts with the victim's OAuth permissions until the token expires or ...[truncated 581 chars]
Remediation
View remediation
"$tmp_file" mv -f "$tmp_file" "$CACHE_FILE" ``` 4. Validate that the cache directory and file are owned by the current user and are not symbolic links before using them. 5. Reject cache paths located in shared or untrusted directories. 6. Consider avoiding persistent token caching where operationally feasible, or use an operating-system credential store. 7. Delete the cache on authentication failures and provide a command for users to invalidate cached tokens after suspected compromise. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (63)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description frames this as a general Google Workspace helper, but the content also teaches credential placement, token retrieval, and token caching behavior. That mismatch can mislead reviewers and agents about the sensitivity of the skill, causing credential-handling behavior to be invoked in contexts where only user-facing document or email actions were expected.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The phrase 'Use PROACTIVELY' combined with 'work with any Google service' is overly broad and encourages automatic invocation for many common requests. In practice, this can trigger high-privilege actions—email, file access, document edits, calendar changes—without sufficient user confirmation or narrowing of scope.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill instructs storing OAuth credentials in a local JSON file and relying on them for broad Google Workspace access. Any skill that normalizes local credential-file handling increases the risk of credential theft, accidental exposure to other tools, or misuse by an over-privileged agent.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Setup

1. Save your ClawEmail credentials JSON to `~/.config/clawemail/credentials.json`
2. Set the environment variable: `export CLAWEMAIL_CREDENTIALS=~/.config/clawemail/credentials.json`

Get credentials at https://clawemail.com — sign up, then visit `/connect/YOUR_PREFIX` to authorize OAuth.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Exporting the credential file path as an environment variable makes sensitive auth material discoverable to subprocesses and shell history patterns. In an agent environment with shell access, environment-based secret discovery materially increases exposure risk.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
## Setup

1. Save your ClawEmail credentials JSON to `~/.config/clawemail/credentials.json`
2. Set the environment variable: `export CLAWEMAIL_CREDENTIALS=~/.config/clawemail/credentials.json`

Get credentials at https://clawemail.com — sign up, then visit `/connect/YOUR_PREFIX` to authorize OAuth.

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The instructions explicitly focus on obtaining and using bearer access tokens, which are immediately usable secrets for all authorized Workspace APIs. In a shell-capable agent context, any workflow that prints or stores such tokens can enable rapid account-wide abuse if intercepted.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
Get credentials at https://clawemail.com — sign up, then visit `/connect/YOUR_PREFIX` to authorize OAuth.

## Getting an Access Token

All API calls need a Bearer token. Use the helper script to refresh and cache it:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

bash
TOKEN=$(~/.openclaw/skills/clawemail/scripts/token.sh)
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://gmail.googleapis.com/gmail/v1/users/me/messages?q=newer_than:7d&maxResults=10" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Read a message

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://gmail.googleapis.com/gmail/v1/users/me/messages/MESSAGE_ID?format=full" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

For plain text body only, use format=minimal and decode the payload. For readable output:

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://gmail.googleapis.com/gmail/v1/users/me/messages/MESSAGE_ID?format=full" \
  | python3 -c "
import json,sys,base64

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents many destructive and privacy-impacting capabilities—reading mail, exporting files, sharing files, deleting files, modifying spreadsheets, creating events—without warning about consent, data sensitivity, or irreversible changes. This omission makes misuse more likely in an agent setting where users may not realize the breadth of access being exercised.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
b'To: recipient@example.com\r\nSubject: Re: Original Subject\r\nIn-Reply-To: <original-message-id>\r\nReferences: <original-message-id>\r\nContent-Type: text/plain; charset=utf-8\r\n\r\nReply body'
).decode()
print(json.dumps({'raw': raw, 'threadId': 'THREAD_ID'}))
" | curl -s -X POST \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d @- \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

Add/remove labels

bash
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"addLabelIds":["LABEL_ID"],"removeLabelIds":["INBOX"]}' \
  "https://gmail.googleapis.com/gmail/v1/users/me/messages/MESSAGE_ID/modify"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

Search files

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://www.googleapis.com/drive/v3/files?q=name+contains+'report'&fields=files(id,name,mimeType,modifiedTime)" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

Create a folder

bash
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name":"My Folder","mimeType":"application/vnd.google-apps.folder"}' \
  "https://www.googleapis.com/drive/v3/files?fields=id,name" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

Upload a file

bash
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  -F "metadata={\"name\":\"report.pdf\"};type=application/json" \
  -F "file=@/path/to/report.pdf;type=application/pdf" \
  "https://www.googleapis.com/upload/drive/v3/files?uploadType=multipart&fields=id,name" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

For Google Docs/Sheets/Slides (export):

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://www.googleapis.com/drive/v3/files/FILE_ID/export?mimeType=application/pdf" -o output.pdf

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

Read a document

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://docs.googleapis.com/v1/documents/DOCUMENT_ID" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

For plain text extraction:

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://docs.googleapis.com/v1/documents/DOCUMENT_ID" \
  | python3 -c "
import json,sys

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

Append text to a document

bash
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"requests":[{"insertText":{"location":{"index":1},"text":"Hello, world!\n"}}]}' \
  "https://docs.googleapis.com/v1/documents/DOCUMENT_ID:batchUpdate"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 290)May include surrounding context.

Read cells

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A1:D10" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

Write cells

bash
curl -s -X PUT -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"values":[["Name","Age","City"],["Alice","30","NYC"],["Bob","25","LA"]]}' \
  "https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A1:C3?valueInputOption=USER_ENTERED" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 306)May include surrounding context.

Append rows

bash
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"values":[["Charlie","35","Chicago"]]}' \
  "https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A:C:append?valueInputOption=USER_ENTERED&insertDataOption=INSERT_ROWS" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 315)May include surrounding context.

Clear a range

bash
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  "https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A1:D10:clear"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

bash
TOKEN=$(~/.openclaw/skills/clawemail/scripts/token.sh)
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"title":"My Presentation"}' \
  "https://slides.googleapis.com/v1/presentations" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 343)May include surrounding context.

Get presentation info

bash
curl -s -H "Authorization: Bearer $TOKEN" \
  "https://slides.googleapis.com/v1/presentations/PRESENTATION_ID" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 350)May include surrounding context.

Add a new slide

bash
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"requests":[{"createSlide":{"slideLayoutReference":{"predefinedLayout":"TITLE_AND_BODY"}}}]}' \
  "https://slides.googleapis.com/v1/presentations/PRESENTATION_ID:batchUpdate" | python3 -m json.tool

Static analysis

No suspicious patterns detected.