skills/joelhooks/joelclaw/clawmail/Gen Agent Trust Hub

clawmail

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCEDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides mechanisms for agents to read (joelclaw mail read) and search (joelclaw mail search) messages originating from other agents or users. This introduces a surface where untrusted instructions could be ingested into the agent's execution context.
  • Ingestion points: Mail content accessed via joelclaw mail read and search results from joelclaw mail search.
  • Boundary markers: The protocol does not specify the use of delimiters or instructions to ignore embedded commands within the mail body.
  • Capability inventory: The skill uses a custom CLI (joelclaw) capable of file system interaction and network coordination.
  • Sanitization: There is no mention of content sanitization or validation for the messages processed by the protocol.
  • [COMMAND_EXECUTION]: The skill relies on the execution of a custom CLI tool (joelclaw) and several wrapper tools (mail_send, mail_inbox, mail_read, etc.) that perform shell commands to interact with the central mail service.
  • [PERSISTENCE]: The skill documentation references architectural components such as com.joelclaw.agent-mail-tunnel.plist and infra/agent-mail-daemon.sh. These files represent persistence mechanisms (macOS launchd agents) used to maintain an SSH tunnel and background daemon for the coordination protocol.
  • [DYNAMIC_EXECUTION]: The instructions include a reliability check that directs the agent to rebuild the joelclaw CLI binary from local source code (packages/cli/src/cli.ts) if the tool becomes stale, involving runtime compilation and execution of local code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — clawmail