Back to skill

Security audit

Resend Email

Security checks for vulnerabilities and agentic risk

Overview

This Resend email skill is mostly clear, but it asks users to activate a third-party plugin with broad Resend account authority without pinning the plugin version or documenting its exact permissions.

Review the ClawLink plugin and account permissions before installing. Only connect a Resend account you are comfortable managing through ClawLink, and treat sends, deletes, domain changes, webhook changes, and API key operations as high-impact actions that should require a clear preview and explicit approval.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Third-Party Plugin Installation and Activation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–46
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: Medium

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The installation procedure retrieves clawlink-plugin from an external package registry without specifying an immutable version, cryptographic digest, or verifiable signature. It then explicitly adds the plugin to the OpenClaw tool allowlist and restarts the gateway, causing the retrieved component to become active.

Although the documentation describes the plugin as verified, the audited project contains no lockfile, checksum, signature, or plugin source code that would allow its reviewed behavior to be tied to the artifact installed later. Consequently, the effective plugin implementation may change after this Skill has been audited. A registry compromise, publisher-account compromise, or malicious future release could expose users to attacker-controlled plugin behavior.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry entry, or upstream release process.
  2. The attacker publishes a modified release under the same mutable clawhub:clawlink-plugin identifier.
  3. A user follows the documented installation command, which retrieves the current package without validating a fixed version or digest.
  4. The subsequent configuration command adds the installed plugin to the OpenClaw tool allowlist.
  5. The gateway restart loads and activates the compromised plugin.
  6. The malicious plugin operates with the permissions available to an enabled OpenClaw plugin and may intercept or manipulate integration operations.

Impact Assessment

Successful exploitation could permit attacker-controlled code to execute within the plugin's runtime context. The ...[truncated 626 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing from a floating package identifier.
  2. Require a publisher signature or cryptographic digest and verify it before installation and activation.
  3. Record the approved version and integrity value in the Skill documentation or a dependency lockfile.
  4. Separate installation from activation: do not allowlist the plugin or restart the gateway until verification succeeds.
  5. Document the plugin's exact permissions and reduce them to the minimum necessary for Resend operations.
  6. Maintain a trusted release process with provenance attestations and periodic dependency review.
  7. Re-audit the plugin whenever its pinned version or integrity digest changes.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says to use the skill when users want to 'inspect email activity, manage audiences, create and send emails, or automate email workflows,' which is a very broad natural-language scope rather than a specific trigger or constrained invocation condition. In a markdown skill file, this can overlap with many ordinary email-related requests and does not provide negative examples or explicit boundaries for when this skill should not activate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes email campaigns, contacts, audiences, domains, templates, and transactional sends, but does not mention credential or API key administration. Exposing tools to create and revoke API keys grants account-level credential management capability that is not clearly justified by the stated end-user email workflow purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.