Email, SMS & phone-call infrastructure for AI agents — send and receive real email and text messages, and place agent-driven outbound voice calls, all programmatically
- vulnerabilitiesattested+9
- capability exposureinferred+35
- tool safetyinferred+12
- trust mitigatorsmixed−3
attestedinferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 8m ago · see ecosystem CVEs →
- C · 41 → C · 53
- highdangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/tmp/obs-code-TQp2mq/agenticmail-a
- highdangerous code
credential logged in 2 file(s)
analyzed v0.9.42 · analyzer v17 · 1d ago
skills & prompt files 6
- agent-rulesagenticmail-agenticmail-b95f52e/AGENTS.md
- agent-rulesagenticmail-agenticmail-b95f52e/CLAUDE.md
- skillagenticmail-agenticmail-b95f52e/packages/openclaw/skill/SKILL.md
- skillagenticmail-agenticmail-b95f52e/plugin/skills/coordinate/SKILL.md
- skillagenticmail-agenticmail-b95f52e/plugin/skills/create-agent/SKILL.md
- skillagenticmail-agenticmail-b95f52e/plugin/skills/install/SKILL.md
danger signals6
- suspicious endpointapi.telegram.orgagenticmail-agenticmail-b95f52e/agenticmail/telegram-bridge/lib/telegram-api.mjs:17
const OFFICIAL_API = 'https://api.telegram.org'; - suspicious endpointapi.telegram.orgagenticmail-agenticmail-b95f52e/packages/core/src/telegram/client.ts:23
export const TELEGRAM_API_BASE = 'https://api.telegram.org'; - over-broad OAuth scopehttps://mail.google.com/agenticmail-agenticmail-b95f52e/packages/api/src/routes/gateway.ts:289
gmailSettingsUrl: 'https://mail.google.com/mail/u/0/#settings/accounts', - over-broad OAuth scopehttps://mail.google.com/agenticmail-agenticmail-b95f52e/packages/core/src/gateway/manager.ts:705
const gmailSettingsUrl = 'https://mail.google.com/mail/u/0/#settings/accounts'; - credential in logscredential in logagenticmail-agenticmail-b95f52e/packages/api/src/realtime-ws.ts:528
console.log(`[realtime-voice] mission=${mission.id} voice-runtime=${runtime.providerId} model=${runtime.model} voice=${runtime.voice} (${runtime.voiceSource}) key=${runtime.apiKeySource}`); - credential in logscredential in logagenticmail-agenticmail-b95f52e/packages/mcp/src/index.ts:502
console.log(` Authorization: Bearer ${authToken}`);
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of agenticmail.