Back to skill

Security audit

Tmp.S252qZs2xo

Security checks for vulnerabilities and agentic risk

Overview

This skill is for Google Classroom administration and is not malicious, but it deserves Review because it can make high-impact account changes through an unpinned npm-run MCP server.

Install only if you trust the gogcli-mcp-classroom npm package and its publisher, pin or review the package version where possible, run it with the least-privileged Google account/scopes, and require explicit confirmation before deleting, archiving, enrolling/removing users, grading/returning work, accepting invitations, or using the escape-hatch command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:20
Finding

Unpinned npm Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–27
Vulnerability Type: Unpinned third-party package execution
Risk Level: High

Vulnerable Code

json
{
  "mcpServers": {
    "gogcli-classroom": {
      "command": "npx",
      "args": ["-y", "gogcli-mcp-classroom"],
      "env": {
        "GOG_ACCOUNT": "you@gmail.com"
      }
    }
  }
}

Technical Analysis

The MCP configuration runs npx -y gogcli-mcp-classroom without specifying an exact package version or validating package integrity. Consequently, npx can retrieve and execute whichever release the npm registry resolves at invocation time. The -y option suppresses the normal installation confirmation.

This creates a supply-chain boundary in which the code executed by the skill can change after the skill itself has been reviewed. If the package, publisher account, registry response, or upstream release process is compromised, a malicious package version could execute locally under the user's account. No malicious payload is embedded in the reviewed project; the vulnerability arises from trusting mutable remote dependency content.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component for gogcli-mcp-classroom.
  2. The attacker publishes a malicious release that is selected by npm as the current version.
  3. A user starts the documented MCP server configuration.
  4. npx -y retrieves the package without requesting confirmation and executes its entry point.
  5. The malicious process runs with the invoking user's local privileges and can access environment data and credentials available to that process.
  6. Where authenticated Google Classroom access is available, the process could misuse the permissions granted to the associated account.

Impact Assessment

Successful exploitation permits arbitrary package code execution wit ...[truncated 541 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact reviewed version, for example gogcli-mcp-classroom@X.Y.Z, rather than resolving the latest release.
  2. Install dependencies through a committed lockfile and use a deterministic installation method such as npm ci.
  3. Verify registry integrity metadata and package provenance before installation.
  4. Remove automatic -y approval where interactive confirmation is operationally feasible.
  5. Prefer installing and reviewing the dependency separately instead of downloading executable code whenever the MCP server starts.
  6. Monitor the package and its transitive dependencies for ownership changes, unexpected releases, and known vulnerabilities.
  7. Grant only the minimum Google OAuth scopes and Classroom permissions required for the intended operation.
  8. Run the MCP server in a restricted environment with limited filesystem, environment-variable, credential, and network access.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description is broad enough to match many generic education-related requests, which can cause the skill to activate in situations the user did not clearly intend. Because this skill exposes powerful Classroom management actions such as creating, deleting, archiving, enrolling, and grading, overbroad invocation increases the risk of unauthorized or mistaken account-affecting operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description advertises destructive and account-affecting actions but does not warn that these operations can modify live courses, rosters, grades, invitations, and announcements. Without a clear warning or confirmation requirement, users may invoke sensitive actions unintentionally, and an agent may proceed without surfacing the operational risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.