T09 · Insecure Skill Coding Practices
- Location
email_bridge/daemon.py:507- Finding
Untrusted Email Headers Are Forwarded into the Agent Session Without Effective Prompt-Injection Isolation
- Content
View full analysis
str: if not sender: return "Unknown" result = re.sub(r'[<>"\']', '', sender) result = remove_invisible_chars(result) if len(result) > max_length: result = result[:max_length] + "..." return result.strip() def sanitize_subject(subject: str, max_length: int = 100) -> str: if not subject: return "(No subject)" result = remove_invisible_chars(subject) result = result.replace('\n', ' ').replace('\r', ' ') if len(result) > max_length: result = result[:max_length].rsplit(' ', 1)[0] + "..." return result.strip() ``` ### Technical Analysis Email sender names and subject lines are fully attacker-controlled. The daemon includes these values in a free-form text notification and submits the notification to OpenClaw using `openclaw system event`. Although the project contains a blacklist-based `sanitize_for_notification()` function, it is not applied to sender names or subject lines. `sanitize_sender()` only removes a small set of punctuation, while `sanitize_subject()` only removes invisible characters and line breaks. Neit ...[truncated 2000 chars]- Remediation
View remediation
