Zoho Email Integration
Complete Zoho Mail integration with OAuth2, REST API (5-10x faster), Clawdbot /email commands, HTML emails, attachments, and batch operations. Security-harde... Skill: Zoho Email Integration Owner: briansmith80 Summary: Complete Zoho Mail integration with OAuth2, REST API (5-10x faster), Clawdbot /email commands, HTML emails, attachments, and batch operations. Security-harde... Tags: latest:2.2.9, security-fix:2.2.7 Version history: v2.2.9 | 2026-02-27T11:10:56.598Z | user Docs: Fix clawhub/clawdhub naming inconsistencies — correct CLI name, slug, badge URL, and version refe
Rank
62
Safety
84
Downloads
3.0k
Updated
Oct 9, 2026
Version
2.2.9
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 3K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 3K downloadsadoption · observed Oct 9, 2026
- Latest release
- 2.2.9release · observed Feb 27, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17ba8phpw0znq9w0nsfn6870s884whw:zoho-email-integration- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-briansmith80-zoho-email-integration/snapshot"
Documentation
CLAWHUB
156,527 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: zoho-email-integration
description: Complete Zoho Mail integration with OAuth2, REST API (5-10x faster), Clawdbot /email commands, HTML emails, attachments, and batch operations. Security-hardened against path traversal and command injection. Perfect for email automation and workflows.
homepage: https://github.com/briansmith80/clawdbot-zoho-email
metadata:
openclaw:
requires:
bins:
- python3
env:
- ZOHO_EMAIL
- ZOHO_PASSWORD
primaryEnv: ZOHO_EMAIL
tokenFile: "~/.clawdbot/zoho-mail-tokens.json"
---
# Zoho Email Integration
**v2.2.8** - Complete Zoho Mail integration with OAuth2 authentication, REST API backend (5-10x faster than IMAP/SMTP), and **Clawdbot extension with /email commands for Telegram/Discord**. **Security-hardened** against path traversal and command injection. Supports HTML emails, attachments, batch operations, and advanced automation workflows.
Choose your authentication: OAuth2 (recommended, secure) or app password (simple setup).
## 🔄 Update to Latest Version
```bash
clawhub install zoho-email-integration --force
```
Or update all skills:
```bash
clawhub update
```
## 🔒 Security Notice (v2.2.5+)
**CRITICAL FIX:** Removed vulnerable JavaScript command handler. If you deployed `email-command.js` from the examples folder, update immediately:
```bash
# Re-download the secure handler
clawhub install zoho-email-integration --force
cp ~/.openclaw/skills/zoho-email-integration/examples/clawdbot-extension/email-command.js /your/deployment/path/
```
The vulnerable version used `execSync` with shell interpolation. The new version uses `spawn` with argument arrays to prevent command injection.
## ✨ Features
### 🔐 Authentication & Performance
- **OAuth2 authentication** - Secure token-based auth with automatic refresh
- **REST API backend** - 5-10x faster operations than IMAP/SMTP
- **Graceful fallback** - Automatically falls back to IMAP if REST API unavailable
- **App password support** - Simple alternative to OAuth2
### 📧 Email Operations
- **📥 Read emails** - Fetch from any folder (Inbox, Sent, Drafts, etc.)
- **🔍 Smart search** - Search by subject, sender, keywords with REST API speed
- **📊 Monitor inbox** - Real-time unread count for notifications
- **📤 Send emails** - Plain text or HTML with CC/BCC support
- **🎨 HTML emails** - Rich formatting with professional templates included
- **📎 Attachments** - Send and download file attachments
### ⚡ Batch & Bulk Operations
- **Batch operations** - Mark, delete, or move multiple emails efficiently
- **Bulk actions** - Search and act on hundreds of emails at once
- **Dry-run mode** - Preview actions before executing for safety
### 🔒 Security
- **No hardcoded credentials** - OAuth2 tokens or environment variables only
- **Automatic token refresh** - Seamless token renewal
- **Encrypted connections** - SSL/TLS for all operations
## 📦 Installation
```bash
clawhub install zoho-email-integration
```
**Requiremexamples/templates/README.md
# HTML Email Templates Professional, ready-to-use HTML email templates for the Zoho Email skill. ## Available Templates ### 📰 newsletter.html **Best for:** Monthly updates, company news, content roundups **Features:** - Modern gradient header - Multiple article sections - Call-to-action buttons - Professional footer - Social media links **Use case:** Send monthly newsletters, product updates, or content digests to subscribers. ### 📢 announcement.html **Best for:** Important notifications, system updates, maintenance alerts **Features:** - Bold banner design - Highlight boxes for key information - Multiple content sections - Professional corporate style - Clear visual hierarchy **Use case:** Announce system maintenance, policy changes, or important company news. ### 🎉 welcome.html **Best for:** New user onboarding, welcome emails **Features:** - Friendly, welcoming design - Step-by-step getting started guide - Emoji support - Social media integration - Engaging call-to-action **Use case:** Welcome new users, guide them through setup, or introduce your service. ### 📝 simple.html **Best for:** Quick, straightforward communications **Features:** - Clean, minimal design - Easy to customize - Professional signature - Good typography - Fast to load **Use case:** General-purpose template for any email, great starting point for custom designs. ## How to Use ### CLI Usage ```bash # Send a template python3 scripts/zoho-email.py send-html [email protected] "Subject" examples/templates/newsletter.html # Preview before sending python3 scripts/zoho-email.py preview-html examples/templates/welcome.html ``` ### Python Usage ```python from scripts.zoho_email import ZohoEmail # Load template with open('examples/templates/newsletter.html', 'r') as f: html = f.read() # Send email zoho = ZohoEmail() zoho.send_html_email( to="[email protected]", subject="Your Monthly Newsletter", html_body=html ) ``` ## Customization Tips ### 1. Replace Placeholder Content All templates contain example text. Simply edit the HTML to replace: - Titles and headings - Body text and descriptions - Links and URLs - Footer information ### 2. Change Colors Each template uses CSS variables or direct color codes. Search for color codes like: - `#667eea` (primary purple) - `#764ba2` (secondary purple) - `#f5576c` (red accent) Replace with your brand colors. ### 3. Add Your Logo Replace the emoji or text in the header with your logo: ```html <img src="https://your-site.com/logo.png" alt="Logo" style="max-width: 200px;"> ``` ### 4. Update Links Replace all `href="#"` with actual URLs: ```html <a href="https://your-site.com/pricing">View Pricing</a> ``` ### 5. Modify Layout Each template uses inline CSS and modern layout techniques. Feel free to: - Add/remove sections - Adjust padding and margins - Change font sizes - Modify button styles ## Email Client Compatibility All templates are designed with maximum compatibility: - ✅ Gmail (Web, Mob
README.md
# Zoho Email Integration for Clawdbot [](https://github.com/briansmith80/clawdbot-zoho-email) [](https://clawhub.com) [](https://opensource.org/licenses/MIT) [](https://github.com/briansmith80/clawdbot-zoho-email/releases) [](SECURITY.md) **v2.2.9** - Complete Zoho Mail integration with OAuth2, REST API backend (5-10x faster), **Clawdbot extension with /email commands**, and advanced email automation features. Perfect for email workflows, monitoring, and bulk operations in your Clawdbot projects. ## 🔒 Security Notice (v2.2.0) **SECURITY UPDATE:** This version fixes critical vulnerabilities identified in security audit. **Upgrade recommended for all users.** **Fixed vulnerabilities:** - ✅ **CRITICAL:** Command injection in JavaScript handler - ✅ **HIGH:** Metadata mismatch (credential requirements) - ✅ **MEDIUM:** Insufficient input validation - ✅ **LOW:** Token file permission enforcement **See [SECURITY.md](SECURITY.md) for details and migration guide.** ## 🚀 Quick Start (recommended path) ```bash # 1) Install clawhub install zoho-email-integration cd zoho-email-integration # (or wherever ClawHub installed it) # 2) Install Python deps (needed for REST API mode) pip3 install -r requirements.txt # 3) Set your mailbox (required for both OAuth + app-password modes) export ZOHO_EMAIL="[email protected]" # 4) OAuth2 setup (recommended: enables REST API + auto token refresh) python3 scripts/oauth-setup.py # 5) Sanity-check everything python3 scripts/zoho-email.py doctor # 6) Test python3 scripts/zoho-email.py unread ``` ### Quick Start (app-password mode) If you don't want OAuth2 yet: ```bash export ZOHO_EMAIL="[email protected]" export ZOHO_PASSWORD="your-app-specific-password" python3 scripts/zoho-email.py doctor python3 scripts/zoho-email.py unread --api-mode imap ``` **OAuth token location (default):** `~/.clawdbot/zoho-mail-tokens.json` ## ✨ Features ### Core Features ✅ **OAuth2 Authentication** - Secure authentication with automatic token refresh ✅ **REST API Backend** - 5-10x faster than IMAP/SMTP (auto-enabled with OAuth2) ✅ **Read & Search** - Search emails with advanced filters ✅ **Send Emails** - Plain text, HTML, CC/BCC support ✅ **Attachments** - Send and download attachments ✅ **HTML Emails** - Send rich-formatted emails with templates ✅ **Batch Operations** - Mark, delete, move multiple emails efficiently ✅ **Folder Management** - Access all folders (Inbox, Sent, Drafts, etc.) ### Performance ⚡ **5-10x faster** operations with REST API mode ⚡ **Connection pooling** for persistent HTTP connections ⚡ **Server-side filtering** reduces data transfer ⚡ **Automatic fallback*
_meta.json
{
"ownerId": "kn780decc8bavz0r6qen0513xh804z45",
"slug": "zoho-email-integration",
"version": "2.2.9",
"publishedAt": 1772190656598
}CHANGELOG.md
# Changelog All notable changes to the Zoho Email Integration skill will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). ## [2.2.8] - 2026-02-27 ### Fixed - **Zoho JP regional IMAP compatibility** — Fixed `UnicodeDecodeError` when connecting to `imap.zoho.jp` and other regional servers that return non-ASCII bytes (NBSP `\xc2\xa0`) in their CAPABILITY response during the initial TLS handshake. **Root cause:** Python's `imaplib` uses ASCII decoding by default. Regional Zoho servers send a non-breaking space character in the CAPABILITY greeting, which crashes the ASCII decoder before authentication can begin. **Fix:** `PatchedIMAP4_SSL` now overrides `open()` to set UTF-8 encoding before the server greeting is read. UTF-8 is a strict superset of ASCII, so this is fully backwards-compatible with all servers. **Note:** v2.2.7 included a community contribution (thanks @SenorToru) that identified and described this bug correctly, but had an implementation error — `_get_capabilities` was defined as a standalone function and never bound to the class, making the fix a no-op. This release corrects that. --- ## [2.2.5] - 2026-02-14 ### 🔒 CRITICAL SECURITY FIX **Vulnerable JavaScript handler removed from distribution.** #### Fixed - **CRITICAL: Removed vulnerable email-command.js** - The examples/clawdbot-extension/ directory contained both a vulnerable (`email-command.js`) and secure (`email-command-SECURE.js`) version of the JavaScript command handler. The vulnerable file used `execSync` with shell interpolation, allowing command injection. The secure version using `spawn` with argument arrays is now the default `email-command.js`. **Impact:** Remote code execution if the vulnerable handler was deployed and user input was processed through /email commands. **Fix:** - Deleted vulnerable `email-command.js` - Renamed `email-command-SECURE.js` to `email-command.js` - Only the secure handler (using `spawn` with argument arrays) now ships #### Upgrade Urgency **IMMEDIATE** - If you deployed the JavaScript handler from examples/, replace it with the new secure version. --- ## [2.2.1] - 2026-02-12 ### 🔒 CRITICAL SECURITY FIXES **Three additional security vulnerabilities discovered and fixed:** #### Fixed - **CRITICAL: Path traversal in attachment download** - The `download_attachment()` function in `scripts/zoho-email.py` used untrusted email attachment filenames directly for file writes. An attacker could send a malicious email with attachment name `../../../../etc/cron.d/backdoor` to write arbitrary files anywhere on the system, leading to remote code execution or privilege escalation. **Fix:** Implemented `_sanitize_filename()` function that: - Strips all directory path components - Removes null bytes and dangerous characters - Prevents hidden files (leading do
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/briansmith80/skills/zoho-email-integration",
"sourceUrl": "https://clawhub.ai/briansmith80/skills/zoho-email-integration",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T10:07:38.187Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-briansmith80-zoho-email-integration/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-briansmith80-zoho-email-integration/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T10:07:38.187Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "3K downloads",
"href": "https://clawhub.ai/briansmith80/zoho-email-integration",
"sourceUrl": "https://clawhub.ai/briansmith80/zoho-email-integration",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T10:07:38.187Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.2.9",
"href": "https://clawhub.ai/briansmith80/zoho-email-integration",
"sourceUrl": "https://clawhub.ai/briansmith80/zoho-email-integration",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-27T11:10:56.598Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-briansmith80-zoho-email-integration/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-briansmith80-zoho-email-integration/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.2.9",
"description": "Docs: Fix clawhub/clawdhub naming inconsistencies — correct CLI name, slug, badge URL, and version references throughout README and SKILL.md",
"href": "https://clawhub.ai/briansmith80/zoho-email-integration",
"sourceUrl": "https://clawhub.ai/briansmith80/zoho-email-integration",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-27T11:10:56.598Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
