Back to skill

Security audit

Zoho Mail

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it gives an agent full mailbox control and installs a mutable remote binary without integrity verification.

Install only if you intend to delegate full read/write Zoho Mail access, including reading sensitive mail, sending replies, and deleting messages. Pin the release, verify a reviewed checksum or signature before installing, restrict who can invoke send/delete commands, protect ZOHO_MAIL_TOKEN_KEY and the token directory, avoid logging pasted OAuth redirect URLs, and revoke the Zoho session if access is no longer needed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:30
Finding

Unverified Remote Executable Download and Installation

Content
View full analysis
Remediation
View remediation
" curl -fL --proto '=https' \ "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/zoho-mail/v${VERSION}/${ARCHIVE}" \ -o "/tmp/${ARCHIVE}" printf '%s %s\n' "${EXPECTED_SHA256}" "/tmp/${ARCHIVE}" | sha256sum --check - tar -xzf "/tmp/${ARCHIVE}" -C ~/.openclaw/bin/ zoho-mail chmod 0755 ~/.openclaw/bin/zoho-mail rm -f "/tmp/${ARCHIVE}" ``` 5. Prefer signed release artifacts and verify the signature against a public key distributed independently of the release repository. 6. Where available, verify build provenance or use reproducible builds so the installed executable can be matched to the audited source. 7. Extract into a staging directory and atomically install only after all validation succeeds. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
internal/oauth/oauth.go:45
Finding

OAuth Authorization Response Is Not Bound to the Login Request

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The skill handles long-lived OAuth credentials and persists refreshed access tokens to disk for continued full mail access, creating a valuable credential target. In the context of a mail skill with read/write/delete permissions, compromise of stored tokens or related terminal-captured auth data could grant broad mailbox control and data exfiltration capability.

Content

Scanner excerpt · CLAUDE.md (reported line 13)May include surrounding context.

md
- `internal/zoho/client.go` — Thin HTTP wrapper over the Zoho Mail REST API (`https://mail.zoho.eu/api`). Account ID is discovered on first API call via `GET /accounts` and cached in `Client.accountID`. All message and folder operations path-encode this ID.
- `internal/oauth/oauth.go` — OAuth2 flow with a localhost redirect (`http://localhost:8080/callback`). `InteractiveLogin` asks the operator to paste the **full redirect URL** back into the terminal (e.g. `http://localhost:8080/callback?code=...`). The code is then extracted from the URL. This differs from google-workspace, which asks for the code value only.
- `internal/crypto/` — AES-256-GCM with HKDF-SHA256 key derivation. Wire format: `salt (16B) || nonce (12B) || ciphertext+tag`. Same pattern as google-workspace.
- `persistingTokenSource` in `cmd/mail.go` — wraps the OAuth2 token source and saves a refreshed token back to disk whenever the access token changes. This keeps the stored token current without manual re-authentication.

## Key differences from google-workspace

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description says the skill provides full read/write Zoho Mail access, which implies mail data operations against Zoho Mail itself. This code chunk does not perform mail read/write actions; instead, it only manages OAuth authentication state. Its primary purpose is obtaining, storing, inspecting, and deleting access tokens, not accessing or modifying mailbox contents. That is a materially different capability set from the declared purpose, so this chunk is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill provides full read/write Zoho Mail access, implying mailbox/API capabilities. The supplied code chunk does not perform any mail access at all. It only manages a local configuration file storing an email address and provides CLI subcommands to show or set that config. This is a materially different primary purpose from the declared one, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The core declared purpose generally matches the main behavior: the code accesses Zoho Mail to read messages and perform write actions like send, reply, delete, and mark read/unread. However, there is a mild mismatch because the description says 'Full read/write Zoho Mail access,' while this chunk exposes only a specific subset of mail operations rather than clearly full mailbox control. Additionally, the code has undeclared supporting capabilities around OAuth token handling and persistence to disk and reading credentials/config from local storage. Those token/config behaviors are ancillary, but they are still additional capabilities not mentioned in the description. Overall, the description is mostly accurate at a high level, but not fully precise, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill provides full read/write Zoho Mail access, but the supplied code only defines generic encryption/decryption routines for protecting data, likely tokens or secrets. It does not connect to Zoho Mail, read or send messages, access mail resources, or implement agent-facing mail capabilities. The mention of "zoho-mail-token" appears only as HKDF context/info and comments, which supports secure token handling rather than mail access itself. This is a clear description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description claims full read/write Zoho Mail access, but this code chunk does not interact with Zoho Mail APIs or perform mail operations. Its actual purpose is credential persistence: managing OAuth tokens locally with encryption and filesystem access. While token handling can support Zoho Mail access, this chunk's behavior is materially narrower and different from the declared primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · cmd/config.go (reported line 74)May include surrounding context.

go
var configSetCmd = &cobra.Command{
	Use:   "set",
	Short: "Update skill configuration",
	Long:  "Set the email address for the Zoho Mail account. Re-run 'zoho-mail auth login' after changing this value.",
	Run: func(cmd *cobra.Command, args []string) {
		cfg, err := loadConfig(configDir)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file describes that the skill can send, reply, delete, and mark messages, but it does not include any warning or caution about modifying or deleting user email data. For markdown files, SQP-2 applies when the skill description omits warnings about behaviours that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Instructing users to paste the full OAuth redirect URL into the terminal unnecessarily exposes sensitive authorization material, including the authorization code and potentially other query parameters such as state. If terminals are logged, monitored, copied into transcripts, or visible to an agent, this increases the risk of token theft or OAuth flow interception.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises full read/write mailbox access, including deletion, but does not prominently warn users about the privacy sensitivity of email contents or the risk of destructive actions. In an agent skill context, broad mailbox scopes materially increase the blast radius of misuse, prompt injection, or operator error.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README repeatedly specifies the EU data centre and EU-region endpoints as required defaults, which imposes a locale constraint in the skill's natural-language instructions. The file does not offer opt-in choice for other regions or explain why the EU-only restriction is required, so it appears to violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The deployment flow explicitly creates persistent secret material on the instance and stores an encrypted OAuth token on a host volume so access survives across invocations. Persistent mailbox credentials increase exposure if the host, container, or service account is compromised, especially given the full read/write mailbox scope.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

md
### 4. Deploy

Merge the Terraform changes to `main`. The deploy workflow will:
- Create SSM parameters for the three secrets
- Update the `.env` file on the instance with `ZOHO_MAIL_TOKEN_KEY`, `ZOHO_CLIENT_ID`, and `ZOHO_CLIENT_SECRET`
- Create the `config/credentials/zoho-mail/` directory

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 73)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-zoho-mail

6. Set the account email

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-zoho-mail

6. Set the account email

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-zoho-mail

6. Set the account email

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 98)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-zoho-mail

6. Set the account email

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-zoho-mail

6. Set the account email

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill requests sensitive capabilities via environment variables and writes an installed binary to the local filesystem, but it does not declare an explicit tool scope such as permissions or allowed-tools. That weakens policy enforcement and makes it harder for operators or agents to understand and constrain what the skill is allowed to access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The skill explicitly relies on persisted OAuth credentials and notes that tokens are stored encrypted at rest, which means mailbox access can survive beyond a single session. Persistent authentication increases the blast radius of host compromise or misconfigured access controls because an attacker may inherit ongoing mail access without re-authentication.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: Zoho Mail
description: Full read/write Zoho Mail access for OpenClaw agents
version: 0.3.0
author: panthrocorp
license: MIT-0

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes high-impact capabilities including reading private email, sending messages, and deleting mail, yet the documentation does not prominently warn about privacy exposure, destructive actions, or the need for operator confirmation. In an agent setting, that increases the risk of accidental harmful actions or overbroad delegation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The installation instructions download a release tag from GitHub and stream a tarball directly into extraction without pinning a checksum, signature, or immutable version. This creates a supply-chain risk where a compromised repository, release, network path, or tag selection could lead to arbitrary code execution on installation.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

Download the latest release binary for linux/arm64 and install to ~/.openclaw/bin/:

bash
TAG=$(curl -fsSL "https://api.github.com/repos/PanthroCorp-Limited/openclaw-skills/releases" \
  | grep -o '"tag_name":"zoho-mail/v[^"]*"' | head -1 | cut -d'"' -f4)
VERSION=${TAG#zoho-mail/v}
curl -fsSL "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/${TAG}/zoho-mail_${VERSION}_linux_arm64.tar.gz" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Go code sends email via the Zoho API and deletes messages, both of which can materially affect user data and external recipients. Although the function comments describe behavior, there is no confirmation prompt, logging, or explicit user-disclosure mechanism in this file for these safety-critical operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation states that all API and auth endpoints use zoho.eu domains only, which imposes a locale/region constraint. Under SQP-3, forcing a specific locale or region without user opt-in or a clearly documented justification can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.