Back to skill

Security audit

google-docs-connector

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Google Docs connector for remote document creation, editing, export, and sharing, with no evidence of hidden local execution or malicious behavior.

Install only if you want an agent to operate on Google Docs through AgentPMT. Confirm before exporting sensitive documents or changing sharing permissions, especially domain-wide or anyone access, and keep OAuth/account secrets out of prompts and logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises broad discovery and activation terms such as document automation, report generation, template creation, and collaborative editing, which overlap with many ordinary writing tasks. That can cause an agent to invoke this external Google Docs tool when a user only wanted local drafting, unnecessarily transmitting content to third-party services and potentially modifying remote documents.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill supports permission changes via share_document but the user-facing description and usage guidance do not prominently warn that it can alter document access, including granting writer/reader/commenter rights or broader sharing modes. In an agent setting, this increases the chance of accidental data exposure or unauthorized collaboration changes if the tool is selected without clear user confirmation.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill can export document contents into downloadable or transferable formats including PDF, DOCX, HTML, and text, but the description does not clearly warn that this may extract and expose sensitive content outside the original access-controlled environment. That omission makes unintended data exfiltration more likely during routine agent use.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The schema exposes a permission-changing action that can share documents with users, groups, domains, or 'anyone', and optionally trigger notification emails, but it provides no explicit user-facing warning that access control is being modified. In an agent setting, this increases the risk of unintended data exposure because an agent may invoke sharing on sensitive documents without making the security consequences clear to the end user.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.