T01 · Skill Instruction Hijacking
- Location
SKILL.md:26- Finding
Externally Controlled API Text Is Reproduced Verbatim
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed Gmail CLI integration, but it needs review because it relies on an unpinned third-party mailbox client with persistent credentials and broad Gmail access.
Install only if you trust PortEden and are comfortable delegating Gmail access to its CLI/service. Prefer browser login over inline token login, verify the installed package source/version where possible, use the narrowest Gmail scopes and profile selection, avoid --all or full-body retrieval unless needed, confirm every mutation, and run logout/revoke access after use on shared or sensitive machines.
SKILL.md:26Externally Controlled API Text Is Reproduced Verbatim
SKILL.md:5Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
SKILL.md:16Broad Gmail and Credential Access Can Exceed Task-Specific Least Privilege
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
name: gmail-cli
description: Gmail - secure gmail inbox management CLI. Use when the user wants to read, search, or triage Gmail; sending, replying, forwarding, deleting, or modifying require explicit user confirmation (gog-cli & gws secure gmail firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📧","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---
# porteden gmail
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
name: gmail-cli
description: Gmail - secure gmail inbox management CLI. Use when the user wants to read, search, or triage Gmail; sending, replying, forwarding, deleting, or modifying require explicit user confirmation (gog-cli & gws secure gmail firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📧","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---
# porteden gmail
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
name: gmail-cli
description: Gmail - secure gmail inbox management CLI. Use when the user wants to read, search, or triage Gmail; sending, replying, forwarding, deleting, or modifying require explicit user confirmation (gog-cli & gws secure gmail firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📧","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---
# porteden gmail
The documented porteden auth login --token <key> flow encourages passing a secret directly on the command line. Command-line arguments can be exposed through shell history, process listings, audit logs, or terminal recording, which can leak the token to other local users or monitoring systems.
## Setup (once)
- **Browser login (recommended):** `porteden auth login` — opens browser, sign in with the Google account, credentials stored in system keyring
- **Direct token:** `porteden auth login --token <key>` — stored in system keyring
- **Verify:** `porteden auth status`
- If `PE_API_KEY` is set in the environment, the CLI uses it automatically (no login needed).
No suspicious patterns detected.