Back to skill

Security audit

Kit Email Marketing Operator

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its email-marketing purpose, but it needs review because it stores powerful Kit credentials with weak, misdescribed protection and gives the agent broad email/account authority.

Review this before installing if the Kit account has a valuable subscriber list. Use a narrowly scoped Kit credential if possible, avoid entering secrets in command-line arguments, do not connect broad MEMORY.md-style files, keep sends in draft/test mode until you confirm audience, subject, send time, and recipient count, and rotate credentials if you previously stored them with this version.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/credentials.js:22
Finding

Predictable Path-Derived Credential Encryption Key

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/credentials.js:123
Finding

Unnecessary Collection and Storage of the Kit API Secret

Content
View full analysis
!creds[field]); if (missing.length > 0) { throw new Error(`Missing required fields: ${missing.join(', ')}`); } // Validate format (Kit API keys have specific patterns) if (!creds.apiKey.startsWith('kit_')) { throw new Error('Invalid API key format (should start with "kit_")'); } if (creds.apiSecret.length < 32) { throw new Error('Invalid API secret (too short)'); } return true; } ``` ```javascript const apiKey = await question('Kit API Key (v4, starts with "kit_"): '); const apiSecret = await question('Kit API Secret: '); const credentials = { apiKey: apiKey.trim(), apiSecret: apiSecret.trim(), createdAt: new Date().toISOString() }; try { validateCredentials(credentials); saveCredentials(credentials); ``` The API client uses only the API key: ```javascript const options = { hostname: BASE_URL, path: `/${API_VERSION}${endpoint}`, method: method.toUpperCase(), headers: { 'Authorization': `Bearer ${this.credentials.apiKey}`, 'Content-Type': 'application/json' } }; ``` ### Technical Analysis The setup process requires, validates, encrypts, and persistently stores both an API key and API secret. The implemented API client authenticates exclusively with `this.credentials.apiKey`; no project code uses `apiSecret`. Collecting a high-value credential that is not needed by any implemented feature violates data-minimization and least-privilege principles. This is especially significant because the credential file is protected by a predictable path-derived encryption key. ### Attack Path 1. The user follows the setup wor ...[truncated 990 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:51
Finding

Overbroad Access to General Agent Memory Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
INSTALLATION.md:239
Finding

Installation Commands Expose Credentials in Shell and Process Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/kit-api.js:70
Finding

Automatic Retries Can Duplicate Non-Idempotent API Operations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALLATION.md (reported line 387)May include surrounding context.

Remove Skill

bash
rm -rf ~/.openclaw/skills/kit-email-operator/

Remove Stored Data

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALLATION.md (reported line 387)May include surrounding context.

Remove Skill

bash
rm -rf ~/.openclaw/skills/kit-email-operator/

Remove Stored Data

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALLATION.md (reported line 393)May include surrounding context.

Remove Stored Data

bash
rm ~/.kit-credentials
rm ~/.kit-voice-samples.json
rm ~/.kit-business-context.json
rm ~/.kit-custom-fields.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALLATION.md (reported line 394)May include surrounding context.

bash
rm ~/.kit-credentials
rm ~/.kit-voice-samples.json
rm ~/.kit-business-context.json
rm ~/.kit-custom-fields.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALLATION.md (reported line 395)May include surrounding context.

bash
rm ~/.kit-credentials
rm ~/.kit-voice-samples.json
rm ~/.kit-business-context.json
rm ~/.kit-custom-fields.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALLATION.md (reported line 396)May include surrounding context.

rm ~/.kit-credentials rm ~/.kit-voice-samples.json rm ~/.kit-business-context.json rm ~/.kit-custom-fields.json

text

**Note:** Your data in Kit (subscribers, broadcasts) is never affected.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
Once approved, use `scripts/kit-api.js` to:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
Once approved, use `scripts/kit-api.js` to:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

md
Once approved, use `scripts/kit-api.js` to:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · INSTALLATION.md (reported line 182)May include surrounding context.

Usage Examples

Create Your First Email

text
You: "Create a nurture email"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide tells users to pass the Kit API key and secret directly on the command line via node scripts/credentials.js store --key="..." --secret="...". Secrets supplied as CLI arguments can be exposed through shell history, audit logs, and process listings to other local users or monitoring tools, which can lead to credential compromise. The surrounding 'security-first' framing makes this more concerning because users may assume the setup is safe end-to-end.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The optional voice training asks users to provide past emails but does not clearly warn about privacy, third-party data, or the possibility of including subscriber PII and confidential business content. That omission can lead users to paste sensitive communications into the system without understanding retention, minimization, or consent implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes sending and scheduling real emails to subscribers without a prominent confirmation/safety warning at the point of action. In an agentic environment, this increases the risk of unintended mass outreach, mis-targeted broadcasts, or premature sends if a user request is ambiguous or the operator assumes approval from conversational context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup guide tells users to invoke the skill with very broad natural-language prompts like 'I want to send an email campaign' and 'Help me write an email to my list' without any explicit activation boundary. In an agentic environment, such generic phrases can cause unintended routing to this skill during ordinary email-assistance requests, increasing the chance of overbroad access to stored credentials, voice-profile data, or outbound email actions when the user did not specifically intend to use this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The post-setup guidance encourages users to 'just ask OpenClaw naturally' with common email-marketing requests, but does not define when this skill should or should not activate. That vagueness makes accidental invocation likely during normal writing help, which can lead the system to access business context, local files, or email-sending capabilities under an overly broad interpretation of user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to collect Kit API credentials and optionally ingest past email samples and business-context files, but it does not require an explicit consent/privacy warning before gathering, analyzing, and persisting that sensitive data. Even if credentials are encrypted at rest, users may unknowingly provide secrets and private communications without clear notice of storage scope, retention, or exposure risks, increasing the chance of accidental disclosure or misuse.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/email-best-practices.md (reported line 1269)May include surrounding context.

md
- ✅ Regular list cleaning

3. **Single Opt-In Only**
   - ❌ No confirmation required
   - ✅ Double opt-in for quality (consider trade-offs)

4. **No Segmentation**

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/kit-personalization.md (reported line 249)May include surrounding context.

md
❌ **Missing fallback for first_name**
→ Results in "Hey ," if name not provided

❌ **Using custom fields without checking they exist**
→ Displays blank or "null"

❌ **Forgetting unsubscribe link**

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/sequence-templates.md (reported line 587)May include surrounding context.

md
(Clean break, no hard feelings)

[Auto-Remove Warning]
If I don't hear from you by [deadline], I'll automatically remove you from the list.

[Gratitude]
Thanks for being here, even if it's time to say goodbye.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring says this method will 'Tag a subscriber', implying it will subscribe the given email to the specified tag. However, the code sends the request to '/tags/{tagId}/subscribe' literally rather than interpolating the tagId variable, so it does not perform the documented operation correctly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI testing paths print full subscriber and broadcast API responses directly to stdout, which can expose sensitive personal or campaign data in terminals, shell history captures, logs, CI output, or shared sessions. In an agent skill context, this is more dangerous because debugging output is often collected automatically and may be visible to other operators or systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The uninstall section includes direct rm commands for deleting stored files but does not clearly warn that these actions are irreversible or recommend verifying paths first. While this is standard shell usage, omission of caution in an installation guide increases the chance of accidental data loss by less experienced users.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README says to "Just ask OpenClaw to help with email marketing" and gives the example "I want to send an email to my list," which is a fairly broad natural-language trigger. In a markdown skill description, this lacks clear scope boundaries or negative examples, so it could encourage unintended invocation for ordinary email-related requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This reference includes multiple subject-line formulas that rely on urgency, curiosity gaps, pattern interrupts, and social proof in ways that can encourage deceptive or manipulative email practices if used without guardrails. Although it briefly warns against clickbait and misleading content, that warning is limited and does not clearly address ethical, reputational, or compliance risks of using examples like false scarcity, vague baiting, or misleading personalization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.