T09 · Insecure Skill Coding Practices
- Location
SKILL.md:13- Finding
OAuth Credential File Setup Does Not Require Restrictive Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google Workspace skill is coherent and not clearly malicious, but it grants broad email, Drive, document, calendar, and form authority without enough user-control and secret-handling safeguards.
Install only if you are comfortable giving an agent broad Google Workspace access. Use a dedicated or least-privileged Google account if possible, restrict credential and cache file permissions, avoid shared machines, and require explicit confirmation before sending email, sharing or deleting Drive files, modifying documents or sheets, changing calendar events, or reading sensitive messages and files.
SKILL.md:13OAuth Credential File Setup Does Not Require Restrictive Permissions
scripts/token.sh:7Cached OAuth Access Token Is Written Without Enforced Owner-Only Permissions
The description frames this as a general Google Workspace helper, but the content also teaches credential placement, token retrieval, and token caching behavior. That mismatch can mislead reviewers and agents about the sensitivity of the skill, causing credential-handling behavior to be invoked in contexts where only user-facing document or email actions were expected.
The phrase 'Use PROACTIVELY' combined with 'work with any Google service' is overly broad and encourages automatic invocation for many common requests. In practice, this can trigger high-privilege actions—email, file access, document edits, calendar changes—without sufficient user confirmation or narrowing of scope.
The skill instructs storing OAuth credentials in a local JSON file and relying on them for broad Google Workspace access. Any skill that normalizes local credential-file handling increases the risk of credential theft, accidental exposure to other tools, or misuse by an over-privileged agent.
## Setup
1. Save your ClawEmail credentials JSON to `~/.config/clawemail/credentials.json`
2. Set the environment variable: `export CLAWEMAIL_CREDENTIALS=~/.config/clawemail/credentials.json`
Get credentials at https://clawemail.com — sign up, then visit `/connect/YOUR_PREFIX` to authorize OAuth.
Exporting the credential file path as an environment variable makes sensitive auth material discoverable to subprocesses and shell history patterns. In an agent environment with shell access, environment-based secret discovery materially increases exposure risk.
## Setup
1. Save your ClawEmail credentials JSON to `~/.config/clawemail/credentials.json`
2. Set the environment variable: `export CLAWEMAIL_CREDENTIALS=~/.config/clawemail/credentials.json`
Get credentials at https://clawemail.com — sign up, then visit `/connect/YOUR_PREFIX` to authorize OAuth.
The instructions explicitly focus on obtaining and using bearer access tokens, which are immediately usable secrets for all authorized Workspace APIs. In a shell-capable agent context, any workflow that prints or stores such tokens can enable rapid account-wide abuse if intercepted.
Get credentials at https://clawemail.com — sign up, then visit `/connect/YOUR_PREFIX` to authorize OAuth.
## Getting an Access Token
All API calls need a Bearer token. Use the helper script to refresh and cache it:
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
TOKEN=$(~/.openclaw/skills/clawemail/scripts/token.sh)
curl -s -H "Authorization: Bearer $TOKEN" \
"https://gmail.googleapis.com/gmail/v1/users/me/messages?q=newer_than:7d&maxResults=10" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -H "Authorization: Bearer $TOKEN" \
"https://gmail.googleapis.com/gmail/v1/users/me/messages/MESSAGE_ID?format=full" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
For plain text body only, use format=minimal and decode the payload. For readable output:
curl -s -H "Authorization: Bearer $TOKEN" \
"https://gmail.googleapis.com/gmail/v1/users/me/messages/MESSAGE_ID?format=full" \
| python3 -c "
import json,sys,base64
The skill documents many destructive and privacy-impacting capabilities—reading mail, exporting files, sharing files, deleting files, modifying spreadsheets, creating events—without warning about consent, data sensitivity, or irreversible changes. This omission makes misuse more likely in an agent setting where users may not realize the breadth of access being exercised.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
b'To: recipient@example.com\r\nSubject: Re: Original Subject\r\nIn-Reply-To: <original-message-id>\r\nReferences: <original-message-id>\r\nContent-Type: text/plain; charset=utf-8\r\n\r\nReply body'
).decode()
print(json.dumps({'raw': raw, 'threadId': 'THREAD_ID'}))
" | curl -s -X POST \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d @- \
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"addLabelIds":["LABEL_ID"],"removeLabelIds":["INBOX"]}' \
"https://gmail.googleapis.com/gmail/v1/users/me/messages/MESSAGE_ID/modify"
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -H "Authorization: Bearer $TOKEN" \
"https://www.googleapis.com/drive/v3/files?q=name+contains+'report'&fields=files(id,name,mimeType,modifiedTime)" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"name":"My Folder","mimeType":"application/vnd.google-apps.folder"}' \
"https://www.googleapis.com/drive/v3/files?fields=id,name" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-F "metadata={\"name\":\"report.pdf\"};type=application/json" \
-F "file=@/path/to/report.pdf;type=application/pdf" \
"https://www.googleapis.com/upload/drive/v3/files?uploadType=multipart&fields=id,name" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
For Google Docs/Sheets/Slides (export):
curl -s -H "Authorization: Bearer $TOKEN" \
"https://www.googleapis.com/drive/v3/files/FILE_ID/export?mimeType=application/pdf" -o output.pdf
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -H "Authorization: Bearer $TOKEN" \
"https://docs.googleapis.com/v1/documents/DOCUMENT_ID" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
For plain text extraction:
curl -s -H "Authorization: Bearer $TOKEN" \
"https://docs.googleapis.com/v1/documents/DOCUMENT_ID" \
| python3 -c "
import json,sys
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"requests":[{"insertText":{"location":{"index":1},"text":"Hello, world!\n"}}]}' \
"https://docs.googleapis.com/v1/documents/DOCUMENT_ID:batchUpdate"
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -H "Authorization: Bearer $TOKEN" \
"https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A1:D10" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X PUT -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"values":[["Name","Age","City"],["Alice","30","NYC"],["Bob","25","LA"]]}' \
"https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A1:C3?valueInputOption=USER_ENTERED" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"values":[["Charlie","35","Chicago"]]}' \
"https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A:C:append?valueInputOption=USER_ENTERED&insertDataOption=INSERT_ROWS" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
"https://sheets.googleapis.com/v4/spreadsheets/SPREADSHEET_ID/values/Sheet1!A1:D10:clear"
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
TOKEN=$(~/.openclaw/skills/clawemail/scripts/token.sh)
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"title":"My Presentation"}' \
"https://slides.googleapis.com/v1/presentations" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -H "Authorization: Bearer $TOKEN" \
"https://slides.googleapis.com/v1/presentations/PRESENTATION_ID" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"requests":[{"createSlide":{"slideLayoutReference":{"predefinedLayout":"TITLE_AND_BODY"}}}]}' \
"https://slides.googleapis.com/v1/presentations/PRESENTATION_ID:batchUpdate" | python3 -m json.tool
No suspicious patterns detected.