T09 · Insecure Skill Coding Practices
- Location
assets/site/unsubscribe.html:102- Finding
Unsubscribe requests are not durably recorded or enforced
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly an event-marketing toolkit, but it handles browser session tokens, lead deletion, mass email, admin exports, and scheduled unsubscribe automation with several unsafe or incomplete controls.
Install only if you are prepared to treat this as a privileged campaign-admin tool. Use a dedicated browser profile for CDP, avoid production service-role keys, review or replace the unsubscribe workflow before sending email, verify consent handling before registration, and do not deploy missing or unaudited Supabase functions.
assets/site/unsubscribe.html:102Unsubscribe requests are not durably recorded or enforced
scripts/renatus_register_guest.py:253Guest registration grants email and SMS consent without explicit authorization
scripts/generate_email_template.py:366Generated email and calendar HTML permits markup and dangerous-link injection
scripts/renatus_leads.py:96Lead exports, unsubscribe files, and recipient logs persist sensitive data with default permissions
references/supabase-setup.md:19Setup instructions provision broad Supabase access and unrelated unauditable components
Referenced artifact was not completely inspected
- `renatus_delete_lead.py` performs deletions — always run with `--dry-run` first
Referenced artifact was not completely inspected
- `renatus_delete_lead.py` performs deletions — always run with `--dry-run` first
Referenced artifact was not completely inspected
- `renatus_delete_lead.py` performs deletions — always run with `--dry-run` first
Referenced artifact was not completely inspected
- `renatus_delete_lead.py` performs deletions — always run with `--dry-run` first
The skill explicitly directs scripts to connect to a local Chrome DevTools endpoint and inspect browser localStorage/cookies to obtain Renatus session tokens. Accessing live browser session material is highly sensitive because any script with CDP access can impersonate the user, extract additional authenticated data, and potentially access unrelated tabs or accounts if browser isolation is weak.
access (not your main browser session)
- `renatus_delete_lead.py` performs deletions — always run with `--dry-run` first
- Rotate credentials after use; revoke tokens that were shared or exposed
- Do not commit real credentials to `config.json` — use the `.example` file and environment variables
**CDP access:** Scripts connect to `http://127.0.0.1:9222` to inspect your browser's localStorage/cookies for Renatus auth tokens. This requires Chrome/Brave launched with `--remote-debugging-port=9222`. The skill does not extract your master Renatus password from CDP — it reads existing session tokens only.
---
name: renatus-icm
description: Run a Renatus event marketing campaign as an ICM (Independent Campaign Manager). Use when managing Renatus event registrations, sending commercial email campaigns, setting up event landing pages, downloading/exporting leads, syncing unsubscribes to Renatus, or performing browser-based guest registration via CDP. Handles: Supabase Edge Function regi
Referenced artifact was not completely inspected
- **CDP Registration** → scripts `renatus_register_guest.py`, `renatus_delete_lead.py`
Referenced artifact was not completely inspected
- **CDP Registration** → scripts `renatus_register_guest.py`, `renatus_delete_lead.py`
Referenced artifact was not completely inspected
- **CDP Registration** → scripts `renatus_register_guest.py`, `renatus_delete_lead.py`
Referenced artifact was not completely inspected
python3 scripts/generate_event_page.py --event-url "https://backoffice.myrenatus.com/Events/EventDetails?eventId=..." --output site/my-event/index.html
Referenced artifact was not completely inspected
python3 scripts/generate_event_page.py --event-url "https://backoffice.myrenatus.com/Events/EventDetails?eventId=..." --output site/my-event/index.html
Referenced artifact was not completely inspected
python3 scripts/add_event.py --event-url "https://backoffice.myrenatus.com/Events/EventDetails?eventId=..." --output site/my-event/index.html
Referenced artifact was not completely inspected
python3 scripts/add_event.py --event-url "https://backoffice.myrenatus.com/Events/EventDetails?eventId=..." --output site/my-event/index.html
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
rpose |
|---|---|---|
| RENATUS_USERNAME | Registration | Back office login |
| RENATUS_PASSWORD | Registration | Back office password |
| RENATUS_EVENT_ID | Registration | Default event GUID |
| LEAD_ADMIN_TOKEN | Export | Admin export auth |
| SUPABASE_URL | Always | Project URL |
| SUPABASE_SERVICE_ROLE_KEY | Always | DB access |
# Add to crontab
0 2 * * 0 /home/umbrel/.openclaw/workspace/scripts/weekly_unsubscribe_sync.sh
# Manual run
CDP_URL=http://127.0.0.1:9222 bash scripts/weekly_unsubscribe_sync.sh
Requirements: Chrome CDP at 9222 + active Renatus session. See email-campaign.md.
# Detect bounces
python3 scripts/handle_bounced_emails.py --check
# Export SMS-ready contacts
python3 scripts/handle_bounced_emails.py --export-sms
# Manually mark bounce
python3 scripts/handle_bounced_emails.py --mark-bounced user@example.com
Referenced artifact was not completely inspected
**Non-CDP scripts:** `renatus_leads.py`, `send_commercial_email_batches.py`, `generate_calendar.py`, `generate_email_template.py`
Documenting lead deletion operations in an email campaign guide introduces destructive administrative capability far beyond simple campaign sending. In the wrong hands or by operator mistake, these commands can permanently remove lead records or process unsubscribe files incorrectly, causing data loss and business impact.
The guide includes a Supabase admin export using an admin token, which is a privileged data extraction mechanism unrelated to basic email sending. Embedding this workflow in the skill normalizes broad access to lead data and increases the chance of credential misuse, unauthorized export, or over-collection of personal information.
The page tells users they have been unsubscribed and that their email will be queued for deletion within 24 hours, but the implemented logic only stores the address in browser localStorage and makes an optional best-effort backend call if a config value exists. This is a deceptive privacy/compliance behavior that can cause users to believe a deletion request was completed when it may never have been sent or processed.
The script logs the user's email address to the browser console, exposing personally identifiable information in a location visible to anyone with browser access, support tooling, shared-device users, or captured debug logs. While limited in scope, unnecessary client-side logging of PII increases privacy risk and can violate data-minimization expectations.
The guide explicitly supports exporting bounced contacts' phone numbers for SMS follow-up, which expands use of personal data beyond the stated email-campaign purpose. Even if operationally convenient, this creates a secondary-contact workflow without any documented consent, minimization, or compliance controls, increasing privacy and abuse risk.
The SMS follow-up export is presented without any privacy, consent, or lawful-use warning despite involving phone numbers derived from bounced email contacts. That omission makes misuse more likely by implying the workflow is routine and acceptable without validating recipient permissions or communication preferences.
The remote-debugging-based unsubscribe sync enables browser-driven actions inside the Renatus backoffice, effectively granting administrative automation capabilities from an email operations guide. This widens the attack surface because anyone following the guide with an authenticated browser session could perform sensitive backoffice actions through a locally exposed debugging interface.
Bulk deletion and unsubscribe-processing commands are documented without prominent warnings about irreversible effects or validation steps. This increases the likelihood of accidental destructive use, especially when processing files that may be malformed, stale, or attacker-influenced.
The guide instructs implementers to collect and transmit personally identifiable information including name, email, phone number, and source URL to a backend service, but it does not mention any privacy notice, consent mechanism, retention policy, or data-handling disclosure. In this context, the omission can lead to noncompliant collection of user data and increased legal and trust risk, especially because the page is intended for public lead registration.
The file states that the system exposes an admin export endpoint for downloading leads, which implies access to personal/business contact data. While authentication details are provided later, the document does not include any explicit warning about handling sensitive lead data, protecting exports, or restricting token sharing.
This section instructs operators to set passwords, service role keys, and admin tokens, but it does not warn that these values are highly sensitive credentials. For a setup guide that handles back-office passwords and privileged Supabase keys, an explicit caution about secure storage, avoiding logs/shell history exposure, and not committing secrets would be expected.
Detected: suspicious.exposed_secret_literal, suspicious.secret_argv_exposure