T02 · Agent Memory Poisoning
- Location
BOOT.md:34- Finding
Persistent Injection of Skill-Controlled Rules into Shared Agent Heartbeat Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s core email-to-calendar purpose is coherent, but it tries to add persistent heartbeat behavior that can keep scanning and modifying email after setup.
Review this before installing. It is not showing remote code execution or data exfiltration, but it can read Gmail, modify Gmail labels, manage Calendar events, write local tracking logs, and add recurring instructions to shared heartbeat memory. Only install if you explicitly want recurring inbox scanning and automatic archiving/mark-read behavior, and check the config plus HEARTBEAT.md for a way to disable or remove those behaviors.
BOOT.md:34Persistent Injection of Skill-Controlled Rules into Shared Agent Heartbeat Memory
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
### Fixed
- **Shell injection / quoting in `event_tracking.py`**: The orphan-cleanup path
used `subprocess.run(..., shell=True)` with an interpolated event ID — the last
instance of the shell-quoting bug class fixed across the other scripts in
v1.13.0/v1.13.1. Converted to safe list-form arguments. Also clears the
`code-execution` finding in ClawHub's static security scan.
The declared description centers on converting emails into Google Calendar events and managing those events. This code chunk instead focuses on finding unread Google calendar-notification emails and disposing of them if their subjects match reply/update/cancellation patterns. That is a Gmail message-cleanup/disposition function, not event extraction or calendar creation/update. While mail disposition is mentioned in the description as a supporting feature, in this chunk it is the sole behavior and it operates on calendar reply notifications specifically, which is materially different from the declared primary purpose. Therefore this chunk does not accurately represent the described functionality and should be flagged as a mismatch.
The declared description is for a full email-to-calendar automation skill, but the actual code shown is only a test runner script. Its primary purpose is executing Python unittests, which is unrelated to scanning Gmail, extracting event data, or managing Google Calendar. This is a material mismatch in behavior and purpose, not merely an omitted implementation detail.
The declared description presents a full-featured email-to-calendar automation skill. However, the provided code chunk is only an empty Python package initializer for tests with a comment. It does not implement any of the described capabilities, nor does it access the claimed resources. Based on this code chunk alone, the actual behavior is materially different from the declared purpose.
The declared description centers on a full email-to-calendar skill integrating with Gmail and Google Calendar. The actual code provided does not implement that workflow; it is only a test suite for a local changelog utility. While some tested concepts loosely align with a described supporting feature (24-hour undo and local state tracking), the chunk’s primary purpose is unrelated test logic around local JSON change records. There is no evidence of Gmail access, calendar management, email parsing, reminder sending, or mail labeling/archiving in this code. Therefore the description does not accurately represent this code chunk.
This code chunk does not implement the declared skill functionality. It is a standalone test module validating helper functions in utils.common. The functions under test are generic formatting/ID/time helpers and are only indirectly related at best. There is no evidence of Gmail reading, Google Calendar management, gog CLI usage, reminder handling, processed-mail actions, undo logic, or any email/calendar workflow. Because the actual code's primary purpose is materially different from the declared description, this is a clear mismatch.
This code chunk is not malicious or performing undeclared sensitive actions; however, it does not implement the declared end-user skill behavior. Instead, it is a narrow internal test module for parsing dates and times. Date/time parsing could be a supporting implementation detail for an email-to-calendar skill, but the actual chunk’s primary purpose is testing that helper logic, not scanning Gmail or managing calendar events. Therefore, the supplied code chunk does not accurately represent the declared description.
The declared description centers on a fully featured Gmail-to-Google-Calendar automation workflow. The provided code chunk does not implement any of those capabilities. Instead, it is strictly a test module for JSON file persistence helpers, using temporary directories and local files. While local JSON storage could be a supporting detail of the declared skill, this specific chunk’s actual behavior is only unit testing that storage layer and shows none of the core declared functionality or resource access (Gmail, Calendar, gog CLI, reminders, labeling, etc.). Therefore the code chunk does not accurately represent the declared purpose and should be flagged as a mismatch.
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
| Thursday | TH |
| Friday | FR |
| Saturday | SA |
| Sunday | SU |
## Key Flags
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Verify the agent can:
- Read emails (list unread, get message body)
- Create calendar events
- Update/delete calendar events
If any capability is missing, inform the user:
The bootstrap instructs the agent to read and potentially modify a global HEARTBEAT.md outside the skill's own directory, creating persistent behavioral changes beyond the immediate user request. This expands the skill's influence into shared agent state and can cause ongoing email/calendar processing behavior to persist across sessions without clear, per-use user consent.
These instructions push persistent email-scanning and invite-handling logic into the agent heartbeat, effectively converting an on-demand skill into a background behavioral modification. That kind of scope expansion is risky because it can lead to continued mailbox monitoring, event creation prompts, and state changes unrelated to the user's immediate invocation of the skill.
The heartbeat content explicitly directs the agent to 'Log all scanning activity silently for audit trail,' which creates undisclosed monitoring and retention of user email-processing activity. Silent logging is dangerous because users may not realize their message metadata or processing history is being stored persistently, raising privacy and consent concerns.
The self-check executes process_calendar_replies.sh during bootstrap, which performs email-processing side effects rather than only validating setup. Running mutation-capable scripts as part of initialization can archive or alter emails without an explicit user action tied to that specific change.
The documented defaults indicate processed emails may be marked read and archived automatically, but BOOT.md does not prominently surface these mailbox-changing behaviors as risky defaults. Automatic disposition of emails can hide messages from the inbox and interfere with the user's normal review workflow if enabled without clear consent.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Fixed
- Stale forward handling: Old emails forwarded today are now properly processed.
- Orphaned events: Events deleted in Google Calendar are now automatically removed from tracking.
## [1.5.0] - 2026-02-02
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Fixed
- Stale forward handling: Old emails forwarded today are now properly processed.
- Orphaned events: Events deleted in Google Calendar are now automatically removed from tracking.
## [1.5.0] - 2026-02-02
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## [1.4.0] - 2026-02-02
### Added
- **Selective Selection**: Users can now cherry-pick events by number (e.g., '1, 2, 3'), 'all', or 'none' instead of binary yes/no confirmation
- **Self-Healing Tracking**: When updating an event that was deleted externally (404/410), automatically removes stale tracking entry and creates a new event
### Removed
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
5. Whole-day events: Timed (9 AM - 5 PM)
6. Multi-day events: Daily recurring
7. Ignore patterns: (none)
8. Auto-create patterns: (none)
9. Email handling: Mark as read and archive (recommended)
Also auto-process calendar replies? (Y/n)
The setup flow presents mailbox-modifying behavior as a recommended default and encourages accepting all defaults with a single Enter press, but it does not clearly warn that processed emails will be marked read, archived, and calendar replies may be auto-processed. In a skill that reads a live inbox, this can cause unintended integrity changes to the user's mailbox and hide messages before the user understands the consequences.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
If you prefer to skip the interactive setup:
mkdir -p ~/.config/email-to-calendar
cat > ~/.config/email-to-calendar/config.json << 'EOF'
{
"provider": "gog",
The prerequisites and surrounding documentation describe broad inbox-reading and calendar-management capabilities, including create, update, and delete actions, without a prominent privacy and integrity warning. Because this skill operates on sensitive email contents and can alter calendar data, insufficient disclosure increases the risk of users granting powerful access without informed consent.
The skill clearly instructs use of shell scripts, local file reads/writes, and stateful logging, but it declares no explicit tool permissions or allowed-tools scope. That mismatch can cause the agent to run with broader-than-expected capabilities or without transparent least-privilege boundaries, which is a real security governance issue for a skill that reads Gmail, modifies Calendar, sends email, and writes local state.
The skill instructs persistent use of MEMORY.md plus detailed local logs, pending invite tracking, and changelog data derived from email content. Because emails can contain sensitive personal, corporate, scheduling, and attendee information, retaining this material in natural-language memory and JSON logs increases privacy exposure, cross-session data leakage risk, and the blast radius of local compromise.
The guidance tells the agent to delete or modify calendar events when cancellation language is detected, but it does not require an explicit confirmation step immediately before taking that destructive action. Because email text can be ambiguous, spoofed, or misparsed, this can lead to unauthorized deletion or corruption of legitimate calendar entries, which is especially risky in a skill that automates Gmail-to-Calendar workflows.
No suspicious patterns detected.