Back to skill

Security audit

School Run

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow Google Sheets helper, but it uses a hardcoded service-account credential path and can modify a live family school schedule without a strong confirmation step.

Only install this if you own or are authorized to manage the referenced school-run spreadsheet. Before use, make sure the service account is scoped only to that spreadsheet, and require the agent to show the exact sheet tab, range, old value, and new value before any update.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports direct updates to a live spreadsheet but does not require explicit user confirmation, warn that writes affect real data, or constrain when modification is appropriate. In practice, an agent could perform unintended or irreversible edits to a family schedule based on ambiguous prompts or mistaken row selection.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
- Always check current data before appending or updating.
- Use `gws sheets spreadsheets values get` to inspect specific dates.
- Use `gws sheets spreadsheets values update` to modify existing rows.
- **Dry-run first** for any write operation.

## Command Templates

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation embeds and depends on a specific local service-account credential file path, revealing sensitive environmental details and normalizing direct use of privileged credentials from the host. In an agent setting, this can encourage unauthorized access patterns, credential misuse, or lateral discovery of secrets beyond the narrow school-run scheduling purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The sheet schema hard-codes an English-language field description ('Who is responsible for dropping Damian and Zachary off at school') and the entire skill is written as English-only operational guidance, with no mention of language choice or locale rationale. Under SQP-3, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.