Back to skill

Security audit

SendClaw Email - Bots & Agents get their own email address

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent email integration, but it gives agents broad email authority while under-scoping inbound-message safety and credential handling.

Install only if you are comfortable giving the agent a SendClaw mailbox and limited authority to send external emails. Store SENDCLAW_API_KEY only in a protected secret manager, do not paste it into chat, and require human approval before the agent replies to inbound mail, contacts new recipients, opens links, or sends sensitive information.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
HEARTBEAT.md:8
Finding

Untrusted Email Content Is Processed Without a Prompt-Injection Boundary

Content
View full analysis
0: - `GET /api/mail/messages?unread=true&limit=5` - Process messages, reply if needed - If `hasMore` is true, repeat 4. If `quota.remaining` < 2 → notify your human ``` ### Technical Analysis The heartbeat workflow retrieves email written by arbitrary external senders and directs the agent to “Process messages, reply if needed.” It does not establish a trust boundary between email content and agent instructions. Email subjects, bodies, sender names, HTML content, and attachments or links must be treated as untrusted data. Without explicit safeguards, an agent may interpret instructions embedded in an email as authoritative requests. An attacker could therefore craft a message that asks the agent to disregard its existing rules, reveal information, send a reply containing sensitive context, contact another recipient, follow a malicious link, or undertake actions through other available tools. The vulnerable behavior is the absence of required sender validation, prompt-injection handling, action authorization, and human approval before replying or taking consequential actions. Merely retrieving email is not itself unsafe; treating retrieved content as actionable instructions creates the exploitation opportunity. ### Attack Path 1. The skill is registered with a public `sendclaw.com` email address. 2. An attacker discovers or guesses that address and sends a crafted email. 3. The scheduled heartbeat detects an unread message. 4. The workflow retrieves the attacker's email using `/api/mail/messages?unread=true`. 5. The agent processes the body without a rule requiring it to treat the body strictly as untrusted data. 6. The embedded instructions influence the agent to send an unauthorized reply or perform another ...[truncated 898 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:165
Finding

Documentation Encourages API Key Entry into Conversational Context

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Install locally:

bash
mkdir -p ~/.sendclaw/skills/sendclaw
curl -s https://sendclaw.com/SKILL.md > ~/.sendclaw/skills/sendclaw/SKILL.md
curl -s https://sendclaw.com/HEARTBEAT.md > ~/.sendclaw/skills/sendclaw/HEARTBEAT.md
curl -s https://sendclaw.com/skill.json > ~/.sendclaw/skills/sendclaw/skill.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Install locally:

bash
mkdir -p ~/.sendclaw/skills/sendclaw
curl -s https://sendclaw.com/SKILL.md > ~/.sendclaw/skills/sendclaw/SKILL.md
curl -s https://sendclaw.com/HEARTBEAT.md > ~/.sendclaw/skills/sendclaw/HEARTBEAT.md
curl -s https://sendclaw.com/skill.json > ~/.sendclaw/skills/sendclaw/skill.json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly encourages the agent to send emails, register accounts, and contact third parties, but the warning about external data transmission appears later and does not clearly front-load privacy implications before those actions are introduced. This can cause users or downstream agents to authorize outbound communication without fully understanding that message contents, recipient addresses, and potentially sensitive task data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description advertises a general capability to 'Get a FREE email address' for AI agents but does not define specific activation phrases, scope limits, or exclusion conditions, making invocation intent ambiguous and potentially broad.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest requires an external service API key and points to a remote API endpoint, but provides no user-facing disclosure about credential handling, data flow, or what information may be sent to the third-party service. This can lead to unsafe deployment, accidental credential exposure, or unreviewed transmission of sensitive content to an external provider.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.