Back to skill

Security audit

SentFromAI email

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed email integration, but it gives an agent broad live-email send, reply, forward, search, and blocking capability without clear per-action user confirmation or tight scoping.

Install only if you intend to let the agent handle real email through SentFromAI. Use a scoped API key where possible, review sends/replies/forwards before they happen, avoid secrets or regulated data in mail handled by the agent, and prefer a pinned or reviewed MCP server install instead of an unpinned `npx` command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables sending, forwarding, and searching real email through an external service but does not provide a clear user-facing warning before transmitting message contents externally. This can lead to unintentional disclosure of sensitive data, especially because inbox contents and forwarded messages may contain private or regulated information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill states that all requests go to https://api.sentfrom.ai/v1 using a bearer API key, establishing an external transmission channel for email data and metadata. Because the capability is to send and receive real email, misuse or prompt injection elsewhere could leverage this channel to disclose sensitive information or communicate externally without adequate user awareness.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
---

You can send and receive real email through SentFromAI. Your API key is in
`SENTFROMAI_API_KEY`; all requests go to `https://api.sentfrom.ai/v1` with
`Authorization: Bearer $SENTFROMAI_API_KEY` and JSON bodies.

If the SentFromAI MCP server is configured (`sentfromai` in `mcp.servers`), prefer its

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to install and run an MCP server via npx ... sentfromai-mcp without pinning an exact package version or integrity source. That creates a supply-chain risk: a future malicious or compromised package version could gain access to the SentFromAI API key and all email contents handled by the tool.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This section directs the agent to use raw HTTP requests to an external API with a bearer token, enabling transmission of mailbox metadata and later message content outside the local trust boundary. In context this is expected functionality, but it is still a genuine data-exfiltration surface because the skill can cause real external communications and expose sensitive mail data to the service.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
tools (`create_inbox`, `send_message`, `reply_to_message`, `search_messages`, …)
over raw HTTP. To set it up:
`openclaw mcp add sentfromai --command npx --arg -y --arg sentfromai-mcp` and put
`SENTFROMAI_API_KEY` in that server's `env`. Otherwise use curl as below.

## Your address

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Listing inboxes via the external API transmits authentication credentials and retrieves account metadata from a third-party service. While this is core functionality, it still expands the attack surface by enabling account enumeration and remote access to mailbox information if the agent is induced to act unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

Create one inbox for yourself once, then reuse it. Check first:

bash
curl -s https://api.sentfrom.ai/v1/inboxes -H "Authorization: Bearer $SENTFROMAI_API_KEY"

If you have none, create one (pick a short local part that fits your name):

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Creating an inbox through the external API provisions a live email address controlled through the service, which can be used to receive and send real-world communications. In the context of an autonomous agent, this is sensitive because it creates a durable external communications channel that could be abused for data leakage, phishing, or unauthorized contact.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

If you have none, create one (pick a short local part that fits your name):

bash
curl -s -X POST https://api.sentfrom.ai/v1/inboxes \
  -H "Authorization: Bearer $SENTFROMAI_API_KEY" -H "Content-Type: application/json" \
  -d '{"local_part": "claw", "display_name": "Claw"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This endpoint sends outbound email to arbitrary recipients with subject and body content, creating a direct exfiltration and impersonation path. In skill context this is intended behavior, but it is particularly dangerous because any compromise, prompt injection, or operator misunderstanding could cause sensitive information to be emailed externally or used in phishing-like workflows.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

Send (client_id makes retries idempotent — use one per logical send):

bash
curl -s -X POST https://api.sentfrom.ai/v1/messages \
  -H "Authorization: Bearer $SENTFROMAI_API_KEY" -H "Content-Type: application/json" \
  -d '{"inbox_id": "<id>", "to": ["person@example.com"], "subject": "…", "text": "…", "client_id": "<unique>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

Polling or searching messages via the external API causes mailbox contents and metadata to be processed by a third-party service and exposed to the agent. This increases risk because inbound email is untrusted and may contain prompt-injection content, while the retrieved data itself may be sensitive or regulated.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Check for new mail (no query returns recent; add query to search, mode=semantic to search by meaning):

bash
curl -s "https://api.sentfrom.ai/v1/messages?limit=10" -H "Authorization: Bearer $SENTFROMAI_API_KEY"

**Reply — always reply to a message id, never compose a fresh email into an

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Replying to an existing message sends agent-generated content into a live external thread, which can disclose sensitive information, confirm the mailbox is active, or continue malicious conversations triggered by inbound prompt injection. Because the skill explicitly handles real email threads, the risk is elevated compared with generic network access.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

existing conversation** (threading headers are set for you):

bash
curl -s -X POST https://api.sentfrom.ai/v1/messages/<message_id>/reply \
  -H "Authorization: Bearer $SENTFROMAI_API_KEY" -H "Content-Type: application/json" \
  -d '{"text": "…"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

Posting blocklist entries to the external service transmits policy decisions and sender patterns to a third party. This is lower impact than message send/reply operations, but it still modifies remote account behavior and could be abused to disrupt communications or reveal relationship metadata.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

Block a noisy sender (enforced server-side, both directions):

bash
curl -s -X POST https://api.sentfrom.ai/v1/lists \
  -H "Authorization: Bearer $SENTFROMAI_API_KEY" -H "Content-Type: application/json" \
  -d '{"kind": "block", "pattern": "spammy.example"}'

Static analysis

No suspicious patterns detected.