OpenClaw plugin for email prompt-injection mitigation - hardens Gmail-triggered automation with sanitization, tool gating, and approval workflows
MailGuard is a specialized security plugin for Gmail-origin session control. It defines 2 tools with partial schema visibility. Tool naming follows verb_noun conventions (policy_check, generate_report), but descriptions are minimal and lack actionable guidance. Parameter schemas are present but incomplete, missing type constraints, enums, and detailed descriptions. The generate_report tool lacks a documented output schema. Error handling is not visible in the provided code excerpt. Overall, this is a domain-specific tool set that addresses a real security need, but falls short of production-grade definition quality due to sparse documentation and incomplete schemas.
Generate a MailGuard security report for the current email session
Check if a tool action is allowed under the current email session policy
Tool descriptions are minimal and lack WHEN/WHY guidance. 'Check if a tool action is allowed...' (66 chars) does not explain when an LLM should invoke this tool vs. letting an action proceed, what constraints it enforces, or whether it blocks or requests approval.
Parameter 'parameters' in policy_check is typed as generic 'object' with minimal description ('Optional parameters for context'). No enum values, format constraints, or examples of valid parameter structures are provided. An LLM cannot reason about what keys/values to pass.
generate_report output schema is not documented. The tool returns 'a MailGuard security report for the current email session' but the response structure (fields, types, pagination) is not visible. LLMs cannot plan downstream actions without knowing what data to extract.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
No error handling guidance visible. If a sessionId is invalid or session policy not initialized, the tool will fail silently. Error responses should guide the LLM: 'Session not found. Call initialize_session first.' [pattern:recovery-guide]
No parameter validation rules documented. 'action' in policy_check is a free-form string; no length limits, character restrictions, or case-sensitivity guidance. LLMs will guess at valid format (e.g. 'send_email' vs 'SendEmail' vs 'SEND_EMAIL').