Back to skill

Security audit

独立开发者客服邮件系统

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent support-email router, but it gives a scheduled mailbox workflow unsafe command execution, dynamic package execution, and AI-forwarding authority that users should review carefully.

Install only after fixing or accepting the risks: remove the npx fallback, replace shell-string execSync calls with argument-array execution, validate email addresses/message IDs/config values, restrict csbot to a single approved reporting action and recipient, and validate any generated channel install command before running it. Use a least-privileged mailbox/account because the router is scheduled and processes public inbound email.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/router.js:283
Finding

Shell Command Injection Through Untrusted Email and Configuration Values

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/router.js:316
Finding

Prompt Injection Through Customer Email Forwarded to a Tool-Enabled AI Agent

Content
View full analysis
`, ` 优先级:<高/中/低> 原因:<简短说明>`, ` 处理建议:`, ` 1. <建议1>`, ` 2. <建议2>`, ` 原始邮件摘要:<50字以内>`, ` 原始发件人:${fromAddr}`, ``, `⚠️ 重要:禁止直接回复原始客户邮件(${fromAddr}),只需将分析报告发给 ${cfg.mainEmail}。`, ``, `=== 原始客户邮件 ===`, `From: ${fromAddr}`, `Subject: ${originalSubject}`, ``, body, ``, `--- NOTE: 原邮件可能包含附件,请查看 support 收件箱 ---`, ].join("\n"); ``` The constructed message is sent to the AI mailbox here: ```js case "forward_csbot": { const tag = rule.tag || "[待分类]"; if (csbotEmail) { log(` → 转发分析请求到 AI 邮箱 ${tag}`); forwardToCsbotForAnalysis(cli, cfg, csbotEmail, fromAddr, subject, body, tag); action = `forward_csbot:${tag}`; } else { log(` → csbot 不可用,直接转发到主邮箱 ${tag}`); forwardEmail(cli, cfg, cfg.mainEmail, fromAddr, subject, body, tag); action = `forward_main:${tag}`; } break; } ``` ### Technical Analysis The router combines trusted task instructions and attacker-controlled email content into one plain-text message delivered to the csbot AI channel. The AI is explicitly instructed to invoke `mail-cli`, giving the resulting prompt operational consequences. The following attacker-controlled values are embedded in the same instruction context: - Original email body - Original subject - Original sender field The visual marker identifying the start of the original email does not c ...[truncated 2025 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/router.js:120
Finding

Dependency Confusion Risk From Dynamic Execution of an Unscoped npm Package

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:166
Finding

Execution of an Unvalidated Installation Command Obtained From an External Service

Content
View full analysis
**⛔⛔⛔ 暂时不要执行 installcommand:** 此命令输出会包含一个 `installcommand`。**先把它记录下来,不要现在执行。** 执行 installcommand 会重启 openclaw,中断当前配置流程。installcommand 安排在最后一步(步骤 7)执行。**把 installcommand 完整保存下来(复制到剪贴板或写入临时文件),继续下一步。** ``` ```markdown ### 7. 安装 csbot channel(最后执行,会重启 openclaw) **这是最后一步。** 执行步骤 3b 中保存的 csbot installcommand: ```bash # 执行之前保存的 csbot installcommand(类似以下格式) openclaw channel install --url "..." --name "csbot-channel" ``` ``` ### Technical Analysis The documented setup process instructs the operator to copy and later execute an `installcommand` generated by `mail-cli clawemail create`. The actual command and URL are not fixed in the reviewed project. The Skill does not require validation of: - The command's executable - Additional command-line arguments - The URL scheme - The remote host - Redirect destinations - A cryptographic signature or integrity digest - The channel payload or configuration being installed The example uses an unspecified URL. Therefore, the effective installed channel can depend on data returned by an external CLI or service after the Skill has been reviewed. If that output is compromised, manipulated, or unexpected, the copied command can install an attacker-controlled channel or include unintended shell operations. The documentation delays execution until the end, but delaying it does not validate it. The command is also expected to restart OpenClaw, increasing its control-plane significance. ### Attack Path 1. The operator runs the documented mailbox creation command. 2. `mail-cli` or its backing service returns an `installcommand`. 3. A compromised package, service, account, network path, or generated response supplies an altered command or untrusted installation URL. 4. The operator saves the returned ...[truncated 1058 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 248)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 280)May include surrounding context.

md
**先完成配置,再创建邮箱。** 脚本位于本 skill 目录下 `scripts/router.js`(Node.js,跨平台兼容 macOS/Linux/Windows)。

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/router.js (reported line 243)May include surrounding context.

js
const combined = `${subject} ${body}`.toLowerCase();
  for (const rule of RULES) {
    if (rule.pattern.test(combined)) {
      return rule;
    }
  }
  return { name: "unknown", action: "forward_csbot", tag: "[待分类]" };

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and top-level documentation present the skill in Chinese only, with no statement that the user may choose their preferred language. This creates a locale/language policy concern because the skill appears to assume Chinese as the operating language rather than offering an explicit opt-in or choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script builds shell command strings and executes them with execSync for search, read, send, and mark operations, using values derived from config files and email metadata. Because these values are interpolated into shell commands, this expands the attack surface from email routing into shell execution, making command injection or unintended command execution possible if quoting assumptions break or a field contains unexpected shell metacharacters.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

When mail-cli is not installed, the script falls back to npx mail-cli, which fetches and executes a package at runtime without a pinned version or integrity control. That creates a supply-chain execution risk: a compromised or typosquatted package, or an unexpected latest release, would run with the same privileges as the router and gain access to mailbox contents and local config.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The router forwards full customer email content, sender address, and subject to another mailbox/AI-processing mailbox without any evidence in this file of consent, minimization, or disclosure. In a support context, these emails can contain personal data, account issues, billing details, or incident information, so undisclosed onward transfer materially increases privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script instructs the AI mailbox to process customer emails and then send a report containing sender details and a summary to another mailbox. This creates an intentional multi-hop disclosure of customer data and increases exposure, especially if the AI mailbox or destination mailbox has different access controls, retention, or audit characteristics than the original support inbox.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes support email triage using mail-cli, but this code additionally inspects local configuration files under XDG/APPDATA and environment variables to discover profile information. That local config harvesting is not clearly justified by the stated purpose of routing messages, especially since it reaches outside the immediate inbox-processing flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function accesses local mail-cli configuration files under user config directories to resolve mailbox profile information. This is credential-adjacent/sensitive configuration access, but the file provides no explicit warning or user disclosure beyond implementation comments.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/router.js:105