T09 · Insecure Skill Coding Practices
- Location
src/tools/gmail-extra.ts:3068- Finding
Forced Gmail label deletion bypasses user confirmation
- Content
View full analysis
Vulnerability Details
File Location:
src/tools/gmail-extra.ts:3068-3077
Vulnerability Type: Unconfirmed destructive account modification
Risk Level: MediumVulnerable Code
ts server.registerTool('gog_gmail_labels_delete', { description: 'Delete a Gmail label.', annotations: { destructiveHint: true, openWorldHint: true }, inputSchema: z.object({ labelIdOrName: z.string().describe('Label ID or name to delete'), account: accountParam, }), }, async ({ labelIdOrName, account }) => { return runOrDiagnose(['gmail', 'labels', 'delete', pos(labelIdOrName), '--force'], { account }); });The same behavior is present in the distributed executable at
dist/index.js:39142-39150.Technical Analysis
The handler always appends
--forcewhen invoking the underlyinggogcommand. This bypasses gogcli's interactive safeguard without requiring an MCP elicitation response, confirmation token, or another code-enforced indication that the end user approved the deletion.The
destructiveHintannotation only describes the operation to the MCP client; it does not technically prevent execution. This contrasts with the project's batch-delete and mail-dispatch handlers, which use enforced confirmation helpers and return before performing the operation when confirmation is absent.The attacker-controlled or untrusted input point is
labelIdOrName, supplied by the Agent or another MCP caller. The crossed trust boundary is between an Agent-generated tool request and explicit end-user authorization for destructive mailbox configuration changes.Attack Path
- An Agent or MCP caller selects
gog_gmail_labels_delete. - The caller supplies the target label through
labelIdOrName. - The handler appends
--forceautomatically. - No user confirmation prompt or confirmation-token validation occurs.
- The command deletes the selected Gmail label using the authenticated account.
Impact Assessment
Successful exploitation can ...[truncated 392 chars]
- An Agent or MCP caller selects
- Remediation
View remediation
Remediation Suggestions
Require a fail-closed confirmation before appending
--force:- Retrieve enough label metadata to show the exact target to the user.
- Invoke the project's existing
requireDispatchConfirmationmechanism. - Bind the account and exact label identifier to the confirmation state or single-use token.
- Return without running gogcli if confirmation is unsupported, declined, expired, invalid, or absent.
- Append
--forceonly after successful confirmation. - Add tests proving that the first call cannot delete, altered arguments invalidate confirmation, and a token cannot be reused.
