clawmail
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCEDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides mechanisms for agents to read (
joelclaw mail read) and search (joelclaw mail search) messages originating from other agents or users. This introduces a surface where untrusted instructions could be ingested into the agent's execution context. - Ingestion points: Mail content accessed via
joelclaw mail readand search results fromjoelclaw mail search. - Boundary markers: The protocol does not specify the use of delimiters or instructions to ignore embedded commands within the mail body.
- Capability inventory: The skill uses a custom CLI (
joelclaw) capable of file system interaction and network coordination. - Sanitization: There is no mention of content sanitization or validation for the messages processed by the protocol.
- [COMMAND_EXECUTION]: The skill relies on the execution of a custom CLI tool (
joelclaw) and several wrapper tools (mail_send,mail_inbox,mail_read, etc.) that perform shell commands to interact with the central mail service. - [PERSISTENCE]: The skill documentation references architectural components such as
com.joelclaw.agent-mail-tunnel.plistandinfra/agent-mail-daemon.sh. These files represent persistence mechanisms (macOS launchd agents) used to maintain an SSH tunnel and background daemon for the coordination protocol. - [DYNAMIC_EXECUTION]: The instructions include a reliability check that directs the agent to rebuild the
joelclawCLI binary from local source code (packages/cli/src/cli.ts) if the tool becomes stale, involving runtime compilation and execution of local code.
Audit Metadata