Back to skill

Security audit

google-docs-connector

Security checks for vulnerabilities and agentic risk

Overview

This Google Docs connector is coherent, but it gives agents broad document editing and sharing power with weak safety friction and unpinned setup commands.

Install only if you trust AgentPMT with the relevant Google Docs account. Use narrow OAuth/account access where possible, confirm document IDs and recipients before tool calls, avoid domain or anyone sharing unless explicitly intended, and prefer pinned or OpenClaw-managed setup instead of copy-pasting unpinned npx commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:342
Finding

Unpinned Third-Party Installation Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:342, SKILL.md:346, SKILL.md:351-352, and SKILL.md:405-406
Vulnerability Type: Unpinned third-party dependencies and mutable installation sources
Risk Level: Medium

Vulnerable Code

markdown
- skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`
bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup

Technical Analysis

The documented setup procedure invokes an unversioned package through npx and installs Skill content from the mutable AgentPMT/agent-skills repository reference. Neither the package runner version nor an immutable repository commit is specified.

Consequently, the content downloaded and processed when a user runs these commands can differ from what existed during this audit. Compromise of the npm package, its publishing account, the upstream repository, or its maintainers could cause users to retrieve malicious code or agent instructions without any modification to the audited project.

This is a supply-chain weakness rather than evidence that the currently documented dependency is malicious.

Attack Path

  1. An attacker compromises the relevant npm package, package-publishing account, upstream repository, or maintainer account.
  2. The attacker publishes a malicious package version or modifies the Skill content referenced by AgentPMT/agent-skills.
  3. A user follows the setup instructions and runs one of the unpinned npx skills add commands.
  4. npx retrieves the current mutable package and repository content rather than a previously audited version.
  5. The malicious dependency executes during installation or installs attacker-controlled Skill instructions.
  6. The payload operates with the privileges available to the inv ...[truncated 689 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npx package to a reviewed exact version instead of relying on the latest available release.
  2. Pin AgentPMT/agent-skills to an immutable commit hash or signed release tag.
  3. Publish cryptographic checksums or signatures for setup artifacts and verify them before installation.
  4. Avoid executing newly downloaded dependencies without inspection; where practical, vendor reviewed setup files with the Skill.
  5. Use package-locking and integrity metadata to make dependency resolution reproducible.
  6. Document the expected source, version, commit, and verification procedure alongside each installation command.
  7. Run installation with the least-privileged account possible and isolate it from unrelated credentials and sensitive files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill enables share_document and permission management but does not prominently require user confirmation or warn about privacy consequences such as granting external access or making documents broadly readable. In a document connector, permission changes are security-sensitive because they can immediately expand data exposure beyond the original audience.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation keywords are broad enough to overlap with ordinary writing and collaboration tasks, which raises the chance that an agent invokes this skill when the user did not explicitly intend document access or modification. In context, unintended invocation could expose document metadata, alter content, export files, or change sharing settings.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill instructs users to install supporting skills via npx skills ... without pinning an exact package or repository version. That creates a supply-chain risk because future or compromised upstream releases could change what gets installed and executed, especially during setup of account-connected tooling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This installation command uses npx skills without a pinned version, so the resolved package and fetched skill content may drift over time. In a connector that later accesses Google Docs and permissions, compromised setup dependencies could lead to unauthorized code or altered instructions entering the workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The setup script again relies on an unpinned npx skills invocation, exposing users to dependency substitution or malicious upstream updates. Because this is part of installation guidance, the risk is more operational than theoretical: users may copy-paste it directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Like the other occurrences, this command depends on the current state of the remote skills package and referenced repository, which may change after publication. That creates avoidable supply-chain exposure for anyone onboarding this skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The reference section repeats an unpinned npx skills install command, preserving the same supply-chain risk in a high-visibility place where users are likely to follow it. Repetition increases exposure because users may trust duplicated instructions as authoritative.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

This is another unpinned package execution example that can resolve to changed or compromised code over time. Since it supports account setup for a remote document-management tool, a malicious dependency could influence authentication flow or tool configuration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 408)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-docs-connector
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-docs-connector
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The share_document action can grant access to a document to arbitrary users, groups, domains, or anyone, yet the schema provides no user-facing warning or friction indicating that this changes access control and may expose sensitive content. In an agent setting, this raises the risk of accidental oversharing through prompt misunderstanding, unsafe automation, or indirect prompt injection that convinces the agent to broaden permissions on an existing document.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The export functionality is described without warning that exported files may leave Google Docs access controls and can be copied, redistributed, or stored insecurely elsewhere. While exporting is expected behavior, the lack of caution increases risk of inadvertent data handling mistakes for sensitive documents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.