Back to skill

Security audit

Tmp.RQhII45DXr

Security checks for vulnerabilities and agentic risk

Overview

This Google Drive skill is coherent in purpose, but it asks users to run an unpinned npm package with authenticated Drive access and offers destructive/sharing tools without clear safety controls.

Review this before installing. Pin the npm package to a specific reviewed version if possible, verify the package publisher and repository relationship, and run it only with a Google account and OAuth scopes appropriate for the files you intend to manage. Require clear confirmation before deletion, replacement, moving, sharing, unsharing, downloading sensitive files, or changing comments and permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned npm Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23–24
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

json
"command": "npx",
"args": ["-y", "gogcli-mcp-drive"],

Technical Analysis

The documented MCP configuration uses npx -y to download and execute gogcli-mcp-drive without pinning an exact package version. The -y option suppresses the installation confirmation, while omission of a version allows the package registry to select the currently resolved release whenever the configuration is used.

Consequently, the code reviewed during one installation may differ from the code executed later. If the package publisher account, npm package, release pipeline, or another relevant supply-chain component is compromised, a malicious release could be delivered automatically. The documentation identifies github.com/chrischall/gogcli-mcp as the source while executing a separately named registry package, so users must independently verify that the registry package is controlled by the expected publisher and corresponds to the reviewed source.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or its release process.
  2. The attacker publishes a malicious version under the gogcli-mcp-drive package name.
  3. A user starts the documented MCP configuration.
  4. npx -y gogcli-mcp-drive resolves, downloads, and executes the malicious release without an interactive confirmation.
  5. The package executes with the operating-system privileges of the MCP host process.
  6. Because the documented prerequisites include an authenticated gogcli installation and the configuration supplies GOG_ACCOUNT, malicious code may attempt to access locally available authentication material or perform Google Drive operations through the authenticated environment.
  7. The attacker can then act within the permissions available to the local pr ...[truncated 891 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package to an exact, reviewed version, for example:

    json
    "command": "npx",
    "args": ["-y", "gogcli-mcp-drive@X.Y.Z"]
    

    Replace X.Y.Z with a version whose source and published artifact have been reviewed.

  2. Prefer a controlled installation process using a lockfile and npm integrity metadata rather than downloading the package dynamically whenever the MCP server starts.

  3. Verify that the npm package publisher, package repository metadata, and referenced GitHub repository belong to the expected maintainers. Confirm that the published artifact is reproducibly derived from the reviewed source.

  4. Use dependency scanning and monitor package ownership, release-signing information, and unexpected changes in transitive dependencies.

  5. Run the MCP server in a restricted environment with minimal filesystem access, limited environment variables, outbound-network controls where practical, and no unrelated credentials.

  6. Grant only the Google OAuth scopes required for the intended Drive operations. Use a dedicated account where feasible and regularly review active tokens, file permissions, and shared-drive access.

  7. Remove automatic confirmation suppression where operationally practical so unexpected installation activity is visible to the user.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is very broad, covering essentially any Drive-related request, which can cause the skill to activate in situations where the user's intent is ambiguous or where a narrower, safer skill should handle the task. Because this skill exposes destructive and privacy-sensitive operations such as delete, share, unshare, move, and download, over-invocation increases the chance of unintended data access or modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool list advertises powerful actions including download, upload/replace, unshare, delete, move, share, and comment manipulation, but provides no warnings or usage constraints for destructive or privacy-impacting operations. In an agentic environment, this omission can normalize high-risk actions without prompting confirmation, increasing the likelihood of accidental data loss, permission changes, or exposure of sensitive Drive contents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.