T09 · Insecure Skill Coding Practices
- Location
script/setup.sh:123- Finding
Command Allowlist Bypass Through Incorrect Long-Option Parsing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent, but it needs Review because its Google Workspace safety wrapper appears vulnerable to an argument-parsing bypass that could undermine blocked Gmail or Calendar actions.
Install only if you are comfortable granting this skill access to the Google account already authorized for gog, and treat the wrapper as needing a security fix before relying on it to block sending email, destructive Gmail actions, or Calendar mutations. Prefer a profile-isolated install directory and verify the wrapper is updated to parse and execute the same normalized arguments before using it with sensitive accounts.
script/setup.sh:123Command Allowlist Bypass Through Incorrect Long-Option Parsing
The skill exposes shell-backed capabilities through the required gog-restricted binary, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. Without an explicit allowlist, an agent platform may grant broader execution latitude than intended or make the shell capability less auditable, increasing the risk of misuse despite the wrapper's internal command restrictions.
This shell script creates and later installs a new executable into a user-writable directory on PATH, which changes the user's command environment. Although the code includes technical status messages and overwrite guards, it does not provide a clear user-facing warning or confirmation before performing this persistent filesystem modification.
No suspicious patterns detected.