Back to skill

Security audit

gogcli-mcp-gmail

Security checks for vulnerabilities and agentic risk

Overview

This is a real Gmail integration, but some destructive Gmail/account-setting delete tools can run without the same user confirmation used elsewhere.

Review before installing. Use this only for an account where you are comfortable granting broad Gmail read/write access, prefer GOG_READONLY for read-only work, and avoid allowing agents to invoke label, filter, send-as, or draft deletion unless you have independently confirmed the exact target.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:3068
Finding

Forced Gmail label deletion bypasses user confirmation

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:3068-3077
Vulnerability Type: Unconfirmed destructive account modification
Risk Level: Medium

Vulnerable Code

ts
server.registerTool('gog_gmail_labels_delete', {
  description: 'Delete a Gmail label.',
  annotations: { destructiveHint: true, openWorldHint: true },
  inputSchema: z.object({
    labelIdOrName: z.string().describe('Label ID or name to delete'),
    account: accountParam,
  }),
}, async ({ labelIdOrName, account }) => {
  return runOrDiagnose(['gmail', 'labels', 'delete', pos(labelIdOrName), '--force'], { account });
});

The same behavior is present in the distributed executable at dist/index.js:39142-39150.

Technical Analysis

The handler always appends --force when invoking the underlying gog command. This bypasses gogcli's interactive safeguard without requiring an MCP elicitation response, confirmation token, or another code-enforced indication that the end user approved the deletion.

The destructiveHint annotation only describes the operation to the MCP client; it does not technically prevent execution. This contrasts with the project's batch-delete and mail-dispatch handlers, which use enforced confirmation helpers and return before performing the operation when confirmation is absent.

The attacker-controlled or untrusted input point is labelIdOrName, supplied by the Agent or another MCP caller. The crossed trust boundary is between an Agent-generated tool request and explicit end-user authorization for destructive mailbox configuration changes.

Attack Path

  1. An Agent or MCP caller selects gog_gmail_labels_delete.
  2. The caller supplies the target label through labelIdOrName.
  3. The handler appends --force automatically.
  4. No user confirmation prompt or confirmation-token validation occurs.
  5. The command deletes the selected Gmail label using the authenticated account.

Impact Assessment

Successful exploitation can ...[truncated 392 chars]

Remediation
View remediation

Remediation Suggestions

Require a fail-closed confirmation before appending --force:

  1. Retrieve enough label metadata to show the exact target to the user.
  2. Invoke the project's existing requireDispatchConfirmation mechanism.
  3. Bind the account and exact label identifier to the confirmation state or single-use token.
  4. Return without running gogcli if confirmation is unsupported, declined, expired, invalid, or absent.
  5. Append --force only after successful confirmation.
  6. Add tests proving that the first call cannot delete, altered arguments invalidate confirmation, and a token cannot be reused.

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:3574
Finding

Permanent draft deletion relies on caller-controlled force flag instead of user confirmation

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:3574-3585
Vulnerability Type: Unconfirmed irreversible content deletion
Risk Level: Medium

Vulnerable Code

ts
server.registerTool('gog_gmail_drafts_delete', {
  description: 'Permanently delete a Gmail draft (not reversible — drafts do not go to Trash). Requires force:true to delete non-interactively.',
  annotations: { destructiveHint: true, openWorldHint: true },
  inputSchema: z.object({
    draftId: z.string().describe('Draft ID'),
    force: z.boolean().optional().describe('Required to delete in this non-interactive context — without it the delete is refused as a safety guard.'),
    account: accountParam,
  }),
}, async ({ draftId, account, force }) => {
  const args: GogArg[] = ['gmail', 'drafts', 'delete', pos(draftId)];
  if (force) args.push('--force');
  return runOrDiagnose(args, { account });
});

The same behavior is present in the distributed executable at dist/index.js:39453-39464.

Technical Analysis

The only application-level gate is the caller-supplied Boolean force. An Agent can set this field itself, so it is not evidence of independent user approval. When it is true, the handler appends --force and immediately invokes the irreversible draft deletion.

The source explicitly states that drafts do not go to Trash and that the deletion cannot be reversed. Nevertheless, unlike gog_gmail_batch_delete and gog_gmail_drafts_send, this handler does not use MCP elicitation or a bound confirmation-token fallback.

The controlled inputs are draftId and force. The authorization boundary crossed is the distinction between an Agent deciding to perform an operation and the user explicitly approving permanent loss of stored email content.

Attack Path

  1. An Agent or MCP caller invokes gog_gmail_drafts_delete.
  2. It supplies a target draftId and sets force: true.
  3. The handler converts that Boolean directly into the gogcli --force opti ...[truncated 586 chars]
Remediation
View remediation

Remediation Suggestions

Replace the caller-controlled force gate with enforced user confirmation:

  1. Fetch the draft before deletion and create a bounded preview containing its recipients, subject, body preview, and attachment names.
  2. Use MCP elicitation when supported.
  3. For clients without elicitation, issue a short-lived, single-use confirmation token bound to the account, draft ID, and current draft content or message ID.
  4. Re-read the draft before deletion and reject confirmation if it changed.
  5. Append --force only after successful validation.
  6. Retain force only as an internal post-confirmation implementation detail, not as public evidence of user consent.

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:4110
Finding

Forced Gmail filter deletion lacks a confirmation gate

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:4110-4118
Vulnerability Type: Unconfirmed destructive Gmail configuration change
Risk Level: Medium

Vulnerable Code

ts
return runOrDiagnose(
  ['gmail', 'settings', 'filters', 'delete', pos(filterId), '--force'],
  { account },
);

This statement is the destructive sink in the gog_gmail_filters_delete handler. The same behavior is present in the distributed executable at dist/index.js:39903-39911.

Technical Analysis

The handler unconditionally appends --force, bypassing the underlying command's interactive deletion safeguard. It does not require an MCP confirmation response or confirmation token before changing account settings.

The attacker-controlled or untrusted input is the target filterId supplied by the Agent or MCP caller. The crossed boundary is between the caller's ability to request a tool operation and the user's authority to approve removal of persistent Gmail automation.

The project applies confirmation to creation of forwarding filters, demonstrating that filter configuration can carry material security consequences. Deletion nevertheless has no equivalent enforced gate.

Attack Path

  1. An Agent or MCP caller obtains or selects a Gmail filter identifier.
  2. It invokes gog_gmail_filters_delete with that identifier.
  3. The handler automatically adds --force.
  4. The authenticated gogcli process deletes the filter without a user confirmation exchange.

Impact Assessment

Deleting a filter can disable persistent mail routing, labeling, archiving, forwarding, spam-handling, or other mailbox automation. Depending on the filter, this can cause messages to be exposed, overlooked, retained, or processed contrary to the user's policy.

The operation is limited to filters in the authenticated Gmail account. No evidence shows malicious intent; the issue is an absent authorization control for a destructive settings change.

Remediation
View remediation

Remediation Suggestions

Add a confirmation workflow before filter deletion:

  1. Fetch the filter and present its criteria and actions in the confirmation preview.
  2. Bind the confirmation to the account, filter ID, and fetched configuration.
  3. Reject missing, declined, expired, reused, or mismatched confirmation.
  4. Re-fetch the filter before deletion to detect changes between preview and execution.
  5. Append --force only after the confirmation helper returns success.
  6. Add regression tests for clients both with and without MCP elicitation support.

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:4208
Finding

Forced send-as alias deletion lacks explicit user authorization

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:4208-4216
Vulnerability Type: Unconfirmed destructive account identity configuration change
Risk Level: Medium

Vulnerable Code

ts
return runOrDiagnose(
  ['gmail', 'settings', 'sendas', 'delete', pos(email), '--force'],
  { account },
);

This statement is the destructive sink in the gog_gmail_sendas_delete handler. The equivalent bundled implementation appears at dist/index.js:39993-40001.

Technical Analysis

The handler automatically supplies --force to gogcli and performs no independent confirmation. A tool argument selecting an alias is therefore enough to authorize deletion of account identity configuration.

The controlled input is the email value supplied by the Agent or MCP caller. The trust boundary is crossed when this caller-selected value is translated directly into a forced account-settings deletion without proving that the end user reviewed and approved the exact alias.

The absence of confirmation is especially notable because the same project requires confirmation when creating a send-as alias, while deletion bypasses gogcli's normal interactive safeguard.

Attack Path

  1. An Agent or MCP caller invokes gog_gmail_sendas_delete.
  2. It supplies the email address of a configured send-as alias.
  3. The handler appends --force without eliciting user approval.
  4. gogcli deletes the alias using the authenticated Gmail account's privileges.

Impact Assessment

Deletion can remove the user's ability to send mail from the selected verified alias and can disrupt workflows or identity separation that depends on it. The action modifies persistent Gmail account settings and may require a new verification process to restore.

The affected scope is the selected Gmail account and alias. The reviewed evidence does not establish malicious intent; it demonstrates an unsafe authorization path.

Remediation
View remediation

Remediation Suggestions

Protect alias deletion with the same fail-closed confirmation infrastructure used for other sensitive operations:

  1. Fetch and display the exact alias and relevant status information.
  2. Bind confirmation to the account and canonical alias address.
  3. Require MCP elicitation acceptance or a valid short-lived, single-use fallback token.
  4. Refuse execution when confirmation cannot be obtained or validated.
  5. Add --force only after confirmation succeeds.
  6. Add tests ensuring that aliases cannot be deleted through a first-call request containing only the target address.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should be used for advanced Gmail operations. However, the supplied code chunk contains only generic data-schema parsing and validation logic from a library akin to Zod, plus localization/error-message infrastructure. There are no Gmail API calls, no auth flows, no mailbox operations, and no email-related business logic. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for advanced Gmail operations, but the code shown only contains locale-specific validation error message generators from Zod. It handles formatting strings for validation failures in many languages and does not access Gmail, authenticate, manipulate email, or expose any mailbox-related behavior. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims this skill is for advanced Gmail operations, but the provided code is clearly a bundled localization section from Zod that maps validation issue codes to translated error strings. There is no evidence of Gmail APIs, message/thread/label handling, forwarding, drafts, attachments, or authentication. This is a materially different primary purpose and an unrelated capability set, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is specifically for advanced Gmail workflows and should involve auth/Gmail tooling. The supplied code chunk shows no Gmail API usage, no email/thread/label/draft handling, no auth logic, and no mailbox operations. Instead, it contains unrelated generic library code for Zod: localized validation error messages and schema compilation/validation internals. This is a clear description-behavior mismatch because the actual code serves a fundamentally different purpose and accesses no Gmail-related resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for advanced Gmail operations. However, the code shown contains generic library code from Zod: constructors for types like string/number/object/union, validation checks, transforms, parsing, and JSON Schema generation/processing. There are no Gmail-specific functions, no calls to Gmail services, no message/thread/label logic, no attachment handling, and no authentication flow. This is a clear description-behavior mismatch because the actual code serves an unrelated primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should handle complex Gmail actions such as threads, labels, drafts, attachments, forwarding, and bulk mailbox operations. However, the supplied code chunk contains no Gmail-specific logic, no Gmail API calls, no email/thread handling, and no mailbox operations. Instead, it defines generic validation and protocol machinery: converting JSON Schema to Zod schemas, traversing schemas, defining MCP request/result/notification schemas, handling OAuth/OpenID metadata structures, and utility/error classes. This is a materially different primary purpose from the declared Gmail functionality, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is specifically for deep Gmail operations. The supplied code chunk instead implements low-level generic protocol machinery: schemas for tools/prompts/resources, request/result validation, JSON-RPC handling, protocol/version negotiation, notifications, subscriptions, caching, and input-required flows. There is no evidence of Gmail APIs, Gmail auth flows, message/thread/label handling, attachments, drafts, forwarding, autoreplies, or any email-specific operations. This is a clear description-behavior mismatch with a materially different primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is specifically for advanced Gmail operations. However, the code chunk contains low-level framework code: sending notifications over a transport, registering request/notification handlers, buffering and deserializing JSON-RPC messages, validating schemas, parsing content types, validating tool names, and AJV/codegen internals. These are generic SDK support components and not Gmail-specific behavior. Because the actual primary purpose is protocol/validation infrastructure rather than Gmail operations, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill should handle in-depth Gmail operations such as reading, organizing, drafting, forwarding, labeling, attachments, and other mailbox actions. The supplied code chunk instead contains unit tests for two helper functions, authoredBodyLines and measureBodyAgreement, validating behavior around removing signatures/sign-offs and comparing authored text across drafts. This is related to email text processing, but it is not itself a Gmail tool or mailbox-operation implementation. Because the primary purpose and capabilities shown in the code are materially different from the declared Gmail-management purpose, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a broad Gmail operations skill intended for acting on a mailbox in depth. The supplied code chunk, however, is not an operational Gmail skill implementation; it is a test file exercising utility functions related to Gmail draft analysis and MIME/body parsing. While the subject matter is Gmail-related, the actual code neither invokes Gmail APIs nor performs the declared end-user capabilities like forwarding, organizing, labeling, or bulk actions. This is a material description-to-behavior mismatch in primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for advanced Gmail operations and should involve Gmail auth/tools. However, the supplied code chunk is only a test configuration file for Vitest. Its primary purpose is to configure test execution and coverage, not to read, send, organize, or otherwise interact with Gmail. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/index.js (reported line 43)May include surrounding context.

js
../node_modules/@chrischall/mcp-utils/dist/caller/index.js
import { AsyncLocalStorage as AsyncLocalStorage2 } from "node:async_hooks";
var storage2 = new AsyncLocalStorage2();
function withCallerCapabilities(capabilities, fn) {
  return capabilities ? storage2.run(capabilities, fn) : fn();
}
function currentCallerCapabilities() {
  return storage2.getStore();
}
var ENVELOPE_CAPABILITIES_KEY = "io.modelcontextprotocol/clientCapabilities";
var ELICITATION_MODES = ["form", "url"];
function isRecord(value) {
  return typeof value === "object" && value !== null && !Array.isArray(value);
}
function callerCapabilities(ctx) {
  const envelope = isRecord(ctx) && isRecord(ctx.mcpReq) ? ctx.mcpReq.envelope : void 0;
  if (isRecord(envelope)) {
    const declared = envelope[ENVELOPE_CAPABILITIES_KEY];
    if (isRecord(declared))
      return declared;
  }
  return currentCallerCapabilities();
}
function callerAcceptsFormElicitation(ctx) {
  const capabilities = callerCapabilities(ctx);
  if (!capa

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/index.js (reported line 18139)May include surrounding context.

js
ams);
}
function keyof(schema) {
  const shape = schema._zod.def.shape;
  return _enum2(Object.keys(shape));
}
var ZodObject = /* @__PURE__ */ $constructor("ZodObject", (inst, def) => {
  _ensureDefaultMemoizer();
  $ZodObjectJIT.init(inst, def);
  ZodType.init(inst, def);
  inst._zod.processJSONSchema = (ctx, json2, params) => objectProcessor(inst, ctx, json2, params);
  util_exports.installLazyProp(inst, "shape", (self) => self._zod.def.shape, false);
}, {
  keyof() {
    return _enum2(Object.keys(this._zod.def.shape));
  },
  catchall(catchall) {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall }));
  },
  passthrough() {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall: unknown() }));
  },
  loose() {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall: unknown() }));
  },
  strict() {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall: never() }));
  },
  strip() {
    return this.clone(util_exports

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · dist/index.js (reported line 27088)May include surrounding context.

js
function validateAsync3() {
      const ruleErrs = gen.let("ruleErrs", null);
      gen.try(() => assignValid((0, codegen_1._)`await `), (e) => gen.assign(valid, false).if((0, codegen_1._)`${e} instanceof ${it.ValidationError}`, () => gen.assign(ruleErrs, (0, codegen_1._)`${e}.errors`), () => gen.throw(e)));
      return ruleErrs;
    }
    function validateSync() {
      const validateErrs = (0, codegen_1._)`${validateRef}.errors`;

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/index.js (reported line 35806)May include surrounding context.

js
var TOKEN_LEFT_BOUNDARY = "(?<![A-Za-z0-9+/])";
var GOOGLE_TOKEN_PATTERNS = [
  new RegExp(`${TOKEN_LEFT_BOUNDARY}ya29\\.[A-Za-z0-9._\\-]+`, "g"),
  // OAuth2 access tokens
  new RegExp(`${TOKEN_LEFT_BOUNDARY}1//[A-Za-z0-9._\\-]+`, "g")
  // OAuth2 refresh tokens
];

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 51)May include surrounding context.

yaml
The Google account to act as. Required for the startup auth bootstrap
      (the refresh token is imported under this email); otherwise defaults to
      gog's single/most recent account.
  - name: GOG_KEYRING_BACKEND
    required: false
    help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 56)May include surrounding context.

yaml
The Google account to act as. Required for the startup auth bootstrap
      (the refresh token is imported under this email); otherwise defaults to
      gog's single/most recent account.
  - name: GOG_KEYRING_BACKEND
    required: false
    help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 61)May include surrounding context.

yaml
The Google account to act as. Required for the startup auth bootstrap
      (the refresh token is imported under this email); otherwise defaults to
      gog's single/most recent account.
  - name: GOG_KEYRING_BACKEND
    required: false
    help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 55)May include surrounding context.

yaml
required: false
    help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS
      keychain — so the keyring lives on the persistent data dir.
  - name: GOG_KEYRING_PASSWORD
    secret: true
    required: false

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/index.js (reported line 36568)May include surrounding context.

js
import { registerExtraGmailTools } from './tools/gmail-extra.js';


// Seed gog's keyring from GOG_CLIENT_ID/SECRET/REFRESH_TOKEN/ACCOUNT when the host injects them.
await bootstrapGogAuth();

await runMcp({

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/index.js (reported line 36579)May include surrounding context.

js
import { registerExtraGmailTools } from './tools/gmail-extra.js';


// Seed gog's keyring from GOG_CLIENT_ID/SECRET/REFRESH_TOKEN/ACCOUNT when the host injects them.
await bootstrapGogAuth();

await runMcp({

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 16)May include surrounding context.

yaml
import { registerExtraGmailTools } from './tools/gmail-extra.js';


// Seed gog's keyring from GOG_CLIENT_ID/SECRET/REFRESH_TOKEN/ACCOUNT when the host injects them.
await bootstrapGogAuth();

await runMcp({

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 20)May include surrounding context.

yaml
import { registerExtraGmailTools } from './tools/gmail-extra.js';


// Seed gog's keyring from GOG_CLIENT_ID/SECRET/REFRESH_TOKEN/ACCOUNT when the host injects them.
await bootstrapGogAuth();

await runMcp({

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 26)May include surrounding context.

yaml
import { registerExtraGmailTools } from './tools/gmail-extra.js';


// Seed gog's keyring from GOG_CLIENT_ID/SECRET/REFRESH_TOKEN/ACCOUNT when the host injects them.
await bootstrapGogAuth();

await runMcp({

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 34)May include surrounding context.

yaml
import { registerExtraGmailTools } from './tools/gmail-extra.js';


// Seed gog's keyring from GOG_CLIENT_ID/SECRET/REFRESH_TOKEN/ACCOUNT when the host injects them.
await bootstrapGogAuth();

await runMcp({

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/index.js:35905

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/index.js:27959

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:35040