Back to skill

Security audit

gogcli-mcp

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Google Workspace automation, but it asks users to run mutable npm MCP packages against a locally authenticated Google account that can affect real Workspace data.

Install only if you trust the npm packages and the gogcli authentication context. Prefer pinned, reviewed package versions, use a dedicated Google account or least-privilege OAuth scopes where possible, and require explicit confirmation before edits, deletes, permission changes, uploads, downloads, or classroom actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned npm Packages Are Downloaded and Executed Without Confirmation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29–42
Vulnerability Type: Supply-chain risk through automatic execution of mutable third-party packages
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "gogcli-docs": {
      "command": "npx",
      "args": ["-y", "gogcli-mcp-docs"],
      "env": { "GOG_ACCOUNT": "you@example.com" }
    },
    "gogcli-sheets": {
      "command": "npx",
      "args": ["-y", "gogcli-mcp-sheets"]
    }
  }
}
json
{ "mcpServers": { "gogcli": { "command": "npx", "args": ["-y", "gogcli-mcp"] } } }

Technical Analysis

The documented configurations use npx -y to resolve, download, and execute npm packages automatically. The package references do not specify exact versions, integrity hashes, lockfiles, or other verification controls. Consequently, the code executed by users may change after this skill has been reviewed.

The executable implementations of these packages are not present in the audited artifact, which contains only SKILL.md. Their behavior therefore cannot be independently verified from the available project content. This is an insecure dependency pattern rather than evidence that the referenced packages are currently malicious.

The risk is amplified because the document states that these MCP servers use a locally authenticated gogcli account. A compromised dependency would execute with the local user's process privileges and could attempt to use credentials or authorization available to that process.

Attack Path

  1. A user adopts one of the documented MCP configurations.
  2. The MCP client invokes npx with -y and an unversioned package name.
  3. npm resolves the package version from mutable registry metadata and downloads it without interactive confirmation.
  4. If the package, a transitive dependency, a maintainer account, or the distribution channel has been compromised, attacker-control ...[truncated 1005 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every npm package to an exact, reviewed version rather than relying on the latest registry resolution, for example gogcli-mcp-docs@x.y.z.
  2. Install dependencies through a committed lockfile and use integrity verification, such as npm ci, in a controlled deployment step.
  3. Avoid npx -y for routine server startup. Preinstall reviewed packages and invoke fixed local binaries instead of downloading executable code on demand.
  4. Verify package provenance, registry ownership, release signatures or attestations, and published integrity metadata before installation.
  5. Include or link to version-matched, auditable source code and document how published artifacts are reproducibly built from that source.
  6. Run each MCP server in a restricted environment with only the required filesystem, network, and environment-variable access.
  7. Grant the Google account only the minimum OAuth scopes required for the selected Workspace API and use a dedicated account where practical.
  8. Keep credentials out of broadly inherited process environments and monitor Google Workspace activity for unexpected access or modifications.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to match many generic requests about documents, files, sheets, slides, or classes, which can cause the agent to invoke a high-privilege Google Workspace skill when the user did not clearly intend it. In this context, over-selection is risky because the skill can act on the authenticated gogcli account and potentially read, modify, or expose Workspace data across Docs, Drive, Sheets, Slides, and Classroom.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation does not clearly warn that it uses the locally authenticated gogcli account and may access or modify the user's Google Workspace data. Without an upfront warning, users or orchestrators may invoke the skill without understanding that actions could affect real documents, spreadsheets, files, permissions, or classroom resources in a live account.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.