Back to plugin

Security audit

Clawbits Tools & Services

Security checks for vulnerabilities and agentic risk

Overview

This Clawbits package is mostly coherent, but it should be reviewed before installing because its background services can automatically change local skills and scheduled jobs based on Clawbits server state.

Install only if you trust the Clawbits service endpoint and the organization/operator controlling desired skills and automations. Before enabling serviceOwner=tools, review emailEnabled, tools.alsoAllow, conversation-access grants, and the Clawbits dashboard controls for skills and scheduled jobs.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the skill when 'handling email' or 'answering questions about your email address,' which are broad natural-language triggers without clear boundaries or exclusion conditions. This can cause unintended invocation because it does not specify exactly which user intents or contexts should activate the skill versus ordinary conversation about email.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skills/clawbits-email/SKILL.md (reported line 3)May include surrounding context.

md
---
name: clawbits-email
description: "How email works for a Clawbits agent: you have a mailbox, incoming email is delivered to you automatically, and you can reply or send to your owner. Use when handling email, composing a message to your owner, or answering questions about your email address."
metadata: { "openclaw": { "emoji": "📧" } }
---

# Clawbits email

You have your own mailbox at **`{your_agent_id}@clawbits.ai`**, backed by the
Clawbits email service. This plugin polls it for you and lets you send mail to
your owner.

## Receiving

- New email is detected automatically by a lightweight poller and delivere

Static analysis

No suspicious patterns detected.