T09 · Insecure Skill Coding Practices
- Location
scripts/email_campaign.py:31- Finding
Path Traversal in Campaign, Subscriber List, and Template File Operations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This email-marketing skill is not clearly malicious, but it handles subscriber data and campaign files with weak boundaries and misleading send/reporting behavior that users should review carefully.
Review before installing or using with real customer data. Use only test lists unless you have consent and compliance controls, avoid untrusted campaign/list/template names, expect local plaintext CSV/JSON files and stdout logs to contain subscriber data, and do not rely on its send status or analytics as proof that emails were delivered.
scripts/email_campaign.py:31Path Traversal in Campaign, Subscriber List, and Template File Operations
README.md:14Unpinned Package Execution in Installation Instructions
scripts/email_campaign.py:132Campaign Send Workflow Fabricates Successful Delivery
The documented behavior claims broader automation, scheduling, and analytics than the described script actions actually support. This mismatch can mislead operators or higher-level agents into trusting the skill with tasks it cannot safely perform, causing unintended sends, missing compliance checks, or incorrect assumptions about monitoring and workflow controls.
The README instructs users to run npx clawhub install yinan-email-marketing without pinning a specific package version. This creates a supply-chain risk because the latest published package or installer behavior could change unexpectedly or be replaced by a malicious release, causing users to install unreviewed code.
The README provides a direct campaign send command but does not warn that it may immediately send marketing emails to real subscriber lists. In an email-marketing skill, this is especially risky because users may test commands in production contexts, leading to accidental bulk email sends, spam complaints, reputational damage, or regulatory noncompliance.
The skill documents executable scripts with capabilities consistent with reading and writing local data, but it declares no explicit tool scope or permissions. That increases the chance an agent or user will invoke file-affecting behavior without clear boundaries, which is risky in a skill that handles subscriber lists and campaign content containing personal data.
The skill centers on bulk email sending and subscriber management but does not present an upfront warning about personal data handling or the real-world consequences of live sends. In this context, omission of safety guidance materially increases the risk of privacy violations, spam, and accidental outreach to real customers.
The quick-start command shows a live send operation without warning that it may immediately email a real recipient list. In an email-marketing skill, this is especially dangerous because users may copy-paste the example directly, leading to unintended bulk messaging, reputational damage, and regulatory exposure.
The code logs subscriber email addresses directly to stdout during campaign sending, which exposes personally identifiable information in console output, CI logs, terminal history, or centralized log collectors. In an email-marketing context, recipient addresses are sensitive customer data, so unnecessary logging increases privacy and compliance risk even if no external attacker is involved.
The add-subscriber flow stores personal data, including email and names, in a local CSV file without any notice, consent handling, retention controls, or protection mechanism. In a marketing skill, collecting and persisting subscriber data is expected functionality, but doing so silently and in plaintext creates privacy, mishandling, and accidental disclosure risks on shared systems.
The subscriber import example includes personally identifiable information but lacks any warning about lawful collection, storage, and protection of that data. While the example alone is not an exploit, in this skill context it normalizes handling customer data without emphasizing consent, minimization, and secure storage.
No suspicious patterns detected.