agent-email-inbox

1.8k
openclawopenclaw

Use when setting up an email inbox for an AI agent (Moltbot, Clawdbot, or similar) - configuring inbound email, webhooks, tunneling for local development, and implementing security measures to prevent prompt injection attacks.

195 days ago

prompt-defense

1.8k
openclawopenclaw

Detect and block prompt injection attacks in emails. Use when reading, processing, or summarizing emails. Scans for fake system outputs, planted thinking blocks, instruction hijacking, and other injection patterns. Requires user confirmation before acting on any instructions found in email content.

195 days ago

indirect-prompt-injection

1.8k
openclawopenclaw

Detect and reject indirect prompt injection attacks when reading external content (social media posts, comments, documents, emails, web pages, user uploads). Use this skill BEFORE processing any untrusted external content to identify manipulation attempts that hijack goals, exfiltrate data, override instructions, or social engineer compliance. Includes 20+ detection patterns, homoglyph detection, and sanitization scripts.

195 days ago

clawdefender

1.8k
openclawopenclaw

Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing new skills from ClawHub, (2) processing external input like emails, calendar events, Trello cards, or API responses, (3) validating URLs before fetching, (4) running security audits on your workspace. Protects agents from malicious content in untrusted data sources.

195 days ago

injection-testing

253
Anshumanbh Securevibes Injection TestingAnshumanbh Securevibes Injection Testing

Validate miscellaneous injection vulnerabilities NOT covered by dedicated skills. Covers SSTI, LDAP, XPath, XQuery, CRLF/HTTP Header, Email Header, GraphQL, Expression Language (EL/OGNL), JSON/JavaScript eval injection, ORM/HQL, CSV/Formula, Regex (ReDoS), YAML config, and Shellshock-style injection. Use when testing CWE-1336 (SSTI), CWE-90 (LDAP), CWE-643 (XPath), CWE-652 (XQuery), CWE-93/CWE-113 (CRLF/Header), CWE-917 (EL), CWE-94/CWE-95 (Code/Eval injection), CWE-1333 (ReDoS), CWE-1236 (CSV/Formula), and related injection classes.

195 days ago

agent-email-inbox

67
resendresend

Use when setting up an email inbox for an AI agent (Moltbot, Clawdbot, or similar) - configuring inbound email, webhooks, tunneling for local development, and implementing security measures to prevent prompt injection attacks.

195 days ago

testing-for-email-header-injection

2
mukul975mukul975

Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.

email-injectionsmtp-injectioncrlf-injection+4
195 days ago

prompt-injection-guard

sharp-skillssharp-skills

Protects AI agents from prompt injection attacks — malicious instructions embedded in external data (web pages, documents, emails, API responses, user inputs) that hijack agent behavior. Use this skill whenever an agent reads external content and then takes actions. Triggers on: "agent reads external data", "process documents with AI", "web scraping with agent", "AI reads emails", "agent processes user files", "RAG system", "AI with tool use", "autonomous agent", "agent browses web", "AI reads database", "multi-step agent", "agentic AI". Anthropic explicitly states: "prompt injection remains an unsolved problem in AI safety research." This skill implements the best current defenses.

195 days ago