Back to skill

Security audit

Claw Mail

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent email integration, but its setup asks users to run an unverified remote Python script and stores mailbox credentials locally without enough safety guidance.

Review before installing. Use this only if you are comfortable sending email content and metadata through ClawMail, and do not run the setup script unless you can verify its source and contents. Treat ~/.clawmail/config.json as a secret, restrict its file permissions, keep it out of repositories and logs, and rotate or remove the credentials when no longer needed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:13
Finding

Unverified Remote Setup Script Download and Execution

Content
View full analysis
Remediation
View remediation
/setup.py" echo " setup.py" | sha256sum --check - python3 setup.py my-agent@clawmail.cc ``` The checksum must be obtained through a trustworthy release process and updated only after the corresponding setup script has been reviewed. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The setup flow creates persistent local credentials for ongoing API access, which expands the blast radius of any later compromise of the agent host or workspace. While persistence is expected for an email integration, the README does not describe lifecycle controls such as revocation, least-privilege scoping, rotation, or secure storage, so the pattern is a real security concern in context.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

Setup

Before using, run the ClawMail setup script to create your inbox:

bash
curl -O https://clawmail.cc/scripts/setup.py

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs users to download and execute a remote Python script directly from an external service without any integrity verification, pinning, or warning about the risk. If the server, DNS, TLS termination, or distribution path is compromised, users could run attacker-controlled code on their machine, making this especially dangerous in an agent skill installation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents network operations that send and retrieve email content, including recipient addresses and message bodies, but does not include an explicit warning that using the skill transmits potentially sensitive user data to an external service. Under the markdown criteria for SQP-2, behaviors affecting privacy should be disclosed clearly to the user.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill instructs users to download and execute a remote Python script directly from the vendor site without any integrity verification, signature check, pinning, or code review step. If the site, CDN, or connection path were compromised, this would enable arbitrary code execution on the host during setup.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

If not already configured, run:

bash
curl -O https://clawmail.cc/scripts/setup.py
python3 setup.py my-agent@clawmail.cc

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup process stores live mailbox credentials in ~/.clawmail/config.json but does not instruct users to protect file permissions or avoid exposing the file to other local users, backups, logs, or repositories. If that file is read by another process or user, the attacker could poll the inbox, read messages, and send mail as the agent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
## API Base URL

`https://api.clawmail.cc/v1`

## Check for New Emails

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
## API Base URL

`https://api.clawmail.cc/v1`

## Check for New Emails

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
## API Base URL

`https://api.clawmail.cc/v1`

## Check for New Emails

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
## API Base URL

`https://api.clawmail.cc/v1`

## Check for New Emails

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
if text: body['text'] = text
        if html: body['html'] = html
        
        r = requests.post(f'{self.base_url}/inboxes/{self.inbox_id}/messages', 
                         headers=self.headers, json=body)
        return r.json()

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The setup instructions state that credentials will be written to ~/.clawmail/config.json but provide no warning about the sensitivity of that file, its permissions, or the implications of local credential storage. In an AI-agent environment, local plaintext credentials can be exposed to other tools, logs, backups, or users if not properly protected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.