Back to skill

Security audit

Email Marketing

Security checks for vulnerabilities and agentic risk

Overview

This email-marketing skill is not clearly malicious, but it handles subscriber data and campaign files with weak boundaries and misleading send/reporting behavior that users should review carefully.

Review before installing or using with real customer data. Use only test lists unless you have consent and compliance controls, avoid untrusted campaign/list/template names, expect local plaintext CSV/JSON files and stdout logs to contain subscriber data, and do not rely on its send status or analytics as proof that emails were delivered.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/email_campaign.py:31
Finding

Path Traversal in Campaign, Subscriber List, and Template File Operations

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:14
Finding

Unpinned Package Execution in Installation Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/email_campaign.py:132
Finding

Campaign Send Workflow Fabricates Successful Delivery

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
83% confidence
Finding

The documented behavior claims broader automation, scheduling, and analytics than the described script actions actually support. This mismatch can mislead operators or higher-level agents into trusting the skill with tasks it cannot safely perform, causing unintended sends, missing compliance checks, or incorrect assumptions about monitoring and workflow controls.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub install yinan-email-marketing without pinning a specific package version. This creates a supply-chain risk because the latest published package or installer behavior could change unexpectedly or be replaced by a malicious release, causing users to install unreviewed code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README provides a direct campaign send command but does not warn that it may immediately send marketing emails to real subscriber lists. In an email-marketing skill, this is especially risky because users may test commands in production contexts, leading to accidental bulk email sends, spam complaints, reputational damage, or regulatory noncompliance.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill documents executable scripts with capabilities consistent with reading and writing local data, but it declares no explicit tool scope or permissions. That increases the chance an agent or user will invoke file-affecting behavior without clear boundaries, which is risky in a skill that handles subscriber lists and campaign content containing personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill centers on bulk email sending and subscriber management but does not present an upfront warning about personal data handling or the real-world consequences of live sends. In this context, omission of safety guidance materially increases the risk of privacy violations, spam, and accidental outreach to real customers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The quick-start command shows a live send operation without warning that it may immediately email a real recipient list. In an email-marketing skill, this is especially dangerous because users may copy-paste the example directly, leading to unintended bulk messaging, reputational damage, and regulatory exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code logs subscriber email addresses directly to stdout during campaign sending, which exposes personally identifiable information in console output, CI logs, terminal history, or centralized log collectors. In an email-marketing context, recipient addresses are sensitive customer data, so unnecessary logging increases privacy and compliance risk even if no external attacker is involved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The add-subscriber flow stores personal data, including email and names, in a local CSV file without any notice, consent handling, retention controls, or protection mechanism. In a marketing skill, collecting and persisting subscriber data is expected functionality, but doing so silently and in plaintext creates privacy, mishandling, and accidental disclosure risks on shared systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The subscriber import example includes personally identifiable information but lacks any warning about lawful collection, storage, and protection of that data. While the example alone is not an exploit, in this skill context it normalizes handling customer data without emphasizing consent, minimization, and secure storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.