T09 · Insecure Skill Coding Practices
- Location
HEARTBEAT.md:8- Finding
Untrusted Email Content Is Processed Without a Prompt-Injection Boundary
- Content
View full analysis
0: - `GET /api/mail/messages?unread=true&limit=5` - Process messages, reply if needed - If `hasMore` is true, repeat 4. If `quota.remaining` < 2 → notify your human ``` ### Technical Analysis The heartbeat workflow retrieves email written by arbitrary external senders and directs the agent to “Process messages, reply if needed.” It does not establish a trust boundary between email content and agent instructions. Email subjects, bodies, sender names, HTML content, and attachments or links must be treated as untrusted data. Without explicit safeguards, an agent may interpret instructions embedded in an email as authoritative requests. An attacker could therefore craft a message that asks the agent to disregard its existing rules, reveal information, send a reply containing sensitive context, contact another recipient, follow a malicious link, or undertake actions through other available tools. The vulnerable behavior is the absence of required sender validation, prompt-injection handling, action authorization, and human approval before replying or taking consequential actions. Merely retrieving email is not itself unsafe; treating retrieved content as actionable instructions creates the exploitation opportunity. ### Attack Path 1. The skill is registered with a public `sendclaw.com` email address. 2. An attacker discovers or guesses that address and sends a crafted email. 3. The scheduled heartbeat detects an unread message. 4. The workflow retrieves the attacker's email using `/api/mail/messages?unread=true`. 5. The agent processes the body without a rule requiring it to treat the body strictly as untrusted data. 6. The embedded instructions influence the agent to send an unauthorized reply or perform another ...[truncated 898 chars]- Remediation
View remediation
