Back to skill

Security audit

Ai Intelligent Email Automation

Security checks for vulnerabilities and agentic risk

Overview

This skill needs Review because it asks users to run unreviewed remote email-automation code and advertises broad email sending, mailbox access, and tracking without clear controls.

Install only after reviewing the external repository at a specific commit, its dependencies, and how it stores or uses email credentials and message data. Require explicit confirmation for sending, bulk mail, auto-replies, and tracking, and avoid using production mailboxes until privacy, consent, and containment are clear.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:43
Finding

Mutable Remote Code Is Retrieved and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43-46
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

bash
git clone https://github.com/openclaw-skills/ai-intelligent-email-automation
cd ai-intelligent-email-automation
pip install -r requirements.txt
python app.py

Technical Analysis

The installation instructions direct users to clone a separate remote repository and execute its application. The repository is not pinned to a specific commit, signed release, or immutable artifact. As a result, the code executed by users can differ from the content present when this skill was audited.

Neither app.py nor requirements.txt is included in the audited artifact, which contains only SKILL.md and skill.json. Their behavior and dependencies therefore cannot be verified from this package. The subsequent pip install also installs unspecified remote dependencies without visible version constraints or integrity hashes.

This is primarily remote payload retrieval and execution: mutable external code becomes the effective implementation after review. The unverified dependency installation further increases supply-chain exposure.

Attack Path

  1. A user follows the installation instructions in SKILL.md.
  2. Git retrieves the current contents of the externally hosted repository rather than an audit-pinned revision.
  3. An attacker who compromises the repository, a maintainer account, or its distribution path modifies app.py or requirements.txt.
  4. The user installs the remotely specified Python packages through pip install -r requirements.txt.
  5. The user runs python app.py, executing the unreviewed payload with the privileges of the current account.
  6. The payload can access resources available to that account. If users configure the advertised SMTP/IMAP functionality, this may include email credentials and message data.

...[truncated 679 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the complete implementation and dependency manifest inside the audited skill package so reviewers can inspect the code that will execute.
  2. If external retrieval is unavoidable, pin the repository to a specific reviewed commit hash rather than cloning the mutable default branch.
  3. Distribute the application through a signed release and verify its cryptographic signature or checksum before installation or execution.
  4. Pin all Python dependencies to exact versions in a lock file and require package hashes, such as with pip install --require-hashes.
  5. Review direct and transitive dependencies for compromised, typosquatted, or abandoned packages.
  6. Run the application with a dedicated least-privileged account or sandbox, restricting filesystem and network access to only what is required.
  7. Document all required SMTP/IMAP permissions, credential-storage behavior, external connections, and email-data handling.
  8. Do not request or load production email credentials until the downloaded code and dependencies have passed integrity and security verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown lists email sending, receiving, analysis, auto-reply, classification, and read/click tracking, but provides no privacy, consent, or monitoring warnings. Because these features inherently process personal communications and may perform surveillance-like tracking, omission of disclosures and safeguards can lead to unauthorized handling of sensitive data, compliance issues, and deceptive user interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description advertises broad email capabilities such as sending, receiving, analyzing, bulk messaging, and auto-replying without defining clear activation boundaries, permission expectations, or user-consent constraints. In an agent ecosystem, this ambiguity can enable overbroad invocation or user misunderstanding, increasing the chance of unintended actions involving external communications and sensitive mailbox data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description and the user-facing markdown content are entirely in Chinese, which can impose a language constraint on users without any opt-in or explanation. The policy allows locale constraints when they are optional or clearly justified, but this file does not offer a language choice or state that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is overly generic and does not clearly define the skill’s intended scope, triggers, or boundaries. For an email automation skill, vague invocation metadata can cause the agent to select the skill in unintended contexts, increasing the chance of inappropriate handling of sensitive email-related actions or data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.