Back to skill

Security audit

Erdmannsilva Gog

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Google Workspace CLI helper, but it combines broad Google account access with an unpinned third-party executable install.

Review the gog CLI source and Homebrew tap before installing, prefer a pinned or trusted release, and grant only the Google services you need. Be especially careful with commands that send email, create calendar items, change Sheets, or export Drive and Docs data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned Executable Dependency from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 6
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"🎮","requires":{"bins":["gog"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/gogcli","bins":["gog"],"label":"Install gog (brew)"}]}}

Technical Analysis

The skill directs the environment to install gogcli from the third-party Homebrew tap steipete/tap. The dependency is not pinned to an immutable version, formula revision, source commit, or cryptographic checksum. Consequently, the code ultimately installed and executed can change after this skill has been reviewed.

The dependency source is external to the audited project, which contains only SKILL.md and _meta.json. Its implementation and installation behavior therefore cannot be verified from this artifact. If the tap, formula, upstream release infrastructure, or maintainer account were compromised, a modified package or installation procedure could be delivered under the expected package name.

This is especially security-sensitive because the installed CLI is instructed to obtain OAuth authorization for Gmail, Calendar, Drive, Contacts, Sheets, and Docs. Although those permissions are consistent with the stated purpose of the skill, a compromised executable could misuse the resulting authorization.

Attack Path

  1. An attacker compromises or gains unauthorized publication access to the third-party Homebrew tap, its formula source, or the referenced upstream release channel.
  2. The attacker modifies the formula or package artifact while preserving the expected steipete/tap/gogcli identity.
  3. A user installs the skill dependency, causing Homebrew to resolve the current mutable formula and execute its installation logic.
  4. The user follows the documented OAuth setup and grants the installed gog executable access to one or mo ...[truncated 1049 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a reviewed, immutable release or formula revision rather than resolving the latest mutable tap content.
  • Verify package artifacts with published cryptographic checksums or signatures before installation.
  • Reference and document the authoritative upstream source and the exact reviewed version.
  • Prefer a trusted distribution channel with reproducible builds and provenance attestations where available.
  • Review the external formula and upstream source before approving installation or version upgrades.
  • Grant only the Google Workspace OAuth services and scopes required for the immediate task.
  • Store OAuth credentials using an operating-system-backed secure credential store and restrict their filesystem permissions.
  • Revoke and rotate OAuth tokens promptly if dependency integrity is questioned.
  • Treat dependency upgrades as security-sensitive changes and repeat source and integrity review before deployment.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
Use `gog` for Gmail/Calendar/Drive/Contacts/Sheets/Docs. Requires OAuth setup.

Setup (once)
- `gog auth credentials /path/to/client_secret.json`
- `gog auth add you@gmail.com --services gmail,calendar,drive,contacts,sheets,docs`
- `gog auth list`

Static analysis

No suspicious patterns detected.