Back to skill

Security audit

validate email

Security checks for vulnerabilities and agentic risk

Overview

The local validator code is limited, but the documentation contradicts its privacy claims by showing hosted API examples that can send email addresses and API credentials to an external service.

Install only if you intend to use the bundled local handler. Do not copy the Claw0x SDK or hosted fetch examples for private or bulk email data unless you explicitly accept sending those addresses to an external service and managing the API key exposure risk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:162
Finding

Contradictory Documentation Encourages Undisclosed Transmission of Email Addresses to an External Service

Content
View full analysis
{ if (input.includes('@')) { const result = await claw0x.call('email-validator', { email: input }); if (!result.valid) { return 'Invalid email format'; } if (result.checks.is_disposable) { return 'Disposable email not allowed'; } } }); ``` ### LangChain Agent ```python from claw0x import Claw0xClient client = Claw0xClient(api_key=os.environ['CLAW0X_API_KEY']) def validate_email(email: str) -> dict: result = client.call('email-validator', {'email': email}) return result # Use in chain email = "user@example.com" validation = validate_email(email) if validation['valid']: print(f"Email is valid with risk score: {validation['risk_score']}") ``` ### Custom Agent ```javascript const response = await fetch('https://api.claw0x.com/v1/call', { method: 'POST', headers: { 'Authorization': `Bearer ${process.env.CLAW0X_API_KEY}`, 'Content-Type': 'application/json' }, body: JSON.stringify({ skill: 'email-validator', input: { email: 'test@example.com' } }) }); const result = await response.json(); console.log(result); ``` ``` ### Technical Analysis Email addresses are personal or customer-sensitive data. The documented SDK calls and direct HTTP request place those addresses ...[truncated 2626 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation repeatedly assures users that the skill runs entirely locally with zero external API calls, but later examples show API-key-based remote invocation patterns. This mismatch can mislead users into transmitting email addresses and credentials to third-party infrastructure under a false privacy assumption.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The '100% local processing' claim is contradicted by later hosted API examples, creating a deceptive privacy and trust boundary for operators. Users may enable the skill in sensitive workflows believing no outbound data flow exists when documented integrations do in fact send data externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The integration examples demonstrate sending email content and API credentials to external services without prominently warning users, despite earlier privacy-focused claims. This omission increases the risk of accidental disclosure of personal data and secrets in environments where operators expect local-only processing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Referencing the hosted API endpoint confirms that at least one documented usage path depends on external network communication. In the context of a skill marketed as local and private, this creates a meaningful security documentation flaw because users may unknowingly route sensitive email addresses off-box.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

Custom Agent

javascript
const response = await fetch('https://api.claw0x.com/v1/call', {
  method: 'POST',
  headers: {
    'Authorization': `Bearer ${process.env.CLAW0X_API_KEY}`,

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Referencing the hosted API endpoint confirms that at least one documented usage path depends on external network communication. In the context of a skill marketed as local and private, this creates a meaningful security documentation flaw because users may unknowingly route sensitive email addresses off-box.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

Custom Agent

javascript
const response = await fetch('https://api.claw0x.com/v1/call', {
  method: 'POST',
  headers: {
    'Authorization': `Bearer ${process.env.CLAW0X_API_KEY}`,

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest says to use the skill when users need to 'verify email format, check disposable emails, or validate bulk email lists,' but it does not define explicit trigger phrases, boundaries, or negative examples. In a manifest-scoped description, this broad wording can make invocation conditions ambiguous rather than narrowly constrained.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.