Back to skill

Security audit

qq-mail-read-send

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended for QQ Mail access, but it needs review because it handles mailbox credentials and email sending with unclear scoping and a mismatched credential path.

Review before installing. Use a dedicated QQ Mail authorization code, store it with owner-only permissions, verify the credential path before use, and require explicit confirmation before any mailbox read or outbound email send.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation and examples are inconsistent about what is actually implemented and how credentials are accessed, which undermines informed consent and safe review. When a skill handles mailbox data and local secrets, behavior-description mismatch can cause operators to approve or invoke capabilities they do not fully understand, increasing the risk of unintended data access or transmission.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill reads a local secrets file containing mailbox credentials, but it does not declare any explicit tool scope or permissions boundary for file access. In an agent environment, undeclared file-read capability increases the chance of overbroad access, weak reviewability, and unintended exposure of sensitive credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill does not clearly warn that using it will access mailbox content and transmit email data through IMAP/SMTP using stored credentials. In a privacy-sensitive context like email, insufficient disclosure raises the risk of users unknowingly authorizing access to sensitive communications and metadata.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad everyday expressions such as '查看邮箱' and '读取邮件', which can cause accidental invocation in loosely related conversations. Because this skill accesses mailbox contents and can send email, unintended triggering could expose sensitive messages or initiate data transmission without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation says credentials are stored in ~/.openclaw/secrets/mail_qq.env, but the sample sender code loads them from a hardcoded Windows Administrator path. This inconsistency can cause the skill to read secrets from an unexpected location, fail open during adaptation, or encourage insecure copying of credentials into privileged or shared paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

SQP-3 applies to natural-language policy issues in all file types. The file presents all instructions and examples only in Chinese, and there is no indication that this locale restriction is optional or required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions in the skill description. The document explains how to send email through QQ SMTP but does not warn that using the function will transmit message content and recipient addresses to an external mail service, which can affect user privacy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.