Back to skill

Security audit

M365 Mailbox (Graph)

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent Microsoft mailbox automation, but it stores OAuth material without explicit file permissions and can create mailbox drafts without enforcing its stated confirmation policy.

Review before installing. Use the narrowest Microsoft Graph scopes possible, avoid offline_access unless needed, and only use this on a trusted single-user machine unless token-cache permissions are hardened. Be aware that enabling draft capability allows draft creation without the stated per-action confirmation check in this version.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_lib.mjs:9
Finding

OAuth Token Cache and Profile Files Are Created Without Explicit Restrictive Permissions

Content
View full analysis
{ if (ctx.cacheHasChanged) { cache = ctx.tokenCache.serialize(); fs.writeFileSync(cachePath, cache, 'utf8'); } }, ``` `scripts/setup.mjs:96-100`: ```js afterCacheAccess: async (ctx) => { if (ctx.cacheHasChanged) { cache = ctx.tokenCache.serialize(); fs.writeFileSync(cachePath, cache, 'utf8'); } }, ``` ### Technical Analysis The Skill stores its MSAL token cache under `~/.openclaw/secrets/m365-mailbox/`. The cache can contain access tokens, refresh-token material, account identifiers, and other authentication state. The directory is created without an explicit `0700` mode, while profile and token-cache files are written without an explicit `0600` mode. Their effective permissions therefore depend on the runtime environment's umask and any permissions already present on the directory or files. A permissive umask or pre-existing broadly accessible file can leave mailbox credentials readable by other local users. The implementation also rewrites existing token-cache files without verifying or correcting their permissions. Merely placing credentials in a directory named `secrets` does not enf ...[truncated 1500 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create-draft.mjs:1
Finding

Configured Draft Confirmation Policy Is Not Enforced

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Known Vulnerable Dependency: uuid==8.3.2 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins uuid to 8.3.2, which the supplied advisory identifies as affected by a missing buffer bounds check in v3/v5/v6 when a buf argument is provided. While this package-lock.json alone does not prove the vulnerable code path is exercised, bundling a version with a known memory-safety/input-validation flaw is a real dependency risk, especially in a mailbox/OAuth-related skill where untrusted identifiers or request data may flow through helper libraries.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency is specified with a caret range (^5.0.4), which allows automatic installation of newer compatible versions rather than a single exact version. This weakens supply-chain reproducibility and can expose consumers to unexpected upstream changes or a compromised release, though the risk in this file alone is limited because it declares only a common library dependency and shows no additional suspicious package sources or install hooks.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"type": "module",
  "description": "OpenClaw skill: Microsoft Graph mailbox automation (M365 business + consumer).",
  "dependencies": {
    "@azure/msal-node": "^5.0.4"
  }
}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function creates a persistent directory at ~/.openclaw/secrets/m365-mailbox, which affects the user's filesystem and stores material in a secrets-related location. There is no confirmation prompt, logging, or explanatory comment in this file to disclose that this write will occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This helper writes arbitrary JSON objects to a file path, and in this module it is closely associated with config and token-cache paths for mailbox secrets. The file performs the write silently, with no prompt, logging, or inline warning indicating that user or credential-related data may be stored on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.