T09 · Insecure Skill Coding Practices
- Location
SKILL.md:83- Finding
Shell Command Injection Through Unvalidated Sheet and Tab Identifiers
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent Google Sheets purpose, but its instructions create real review concerns around command execution, unsafe cache paths, and plaintext retention of private sheet data.
Review this skill before installing. Use it only with sheets you are comfortable exposing to the OpenClaw runtime, avoid private sheets unless caching is fixed or disabled, and do not run it on untrusted Sheet IDs or attacker-controlled tab names until command construction and cache path handling are hardened.
SKILL.md:83Shell Command Injection Through Unvalidated Sheet and Tab Identifiers
SKILL.md:150Path Traversal Enables Filesystem Writes and Recursive Deletion Outside the Cache Directory
SKILL.md:166Private Spreadsheet Contents Are Persisted in Plaintext Without Permission Hardening
The trigger language is extremely broad, including generic words like 'sheet' and casual phrases such as 'check my sheet,' which are likely to overlap with unrelated user requests. Overbroad activation can cause this skill to engage unexpectedly, leading to unnecessary external requests, credential use, or access to spreadsheet-linked data when the user did not intend to invoke it.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
| python3 -c "import sys,json; d=json.load(sys.stdin); [print(s['properties']['title']) for s in d['sheets']]"
curl -s "https://sheets.googleapis.com/v4/spreadsheets/{SHEET_ID}/values/{TAB_NAME}!A1:Z1000?key={GOOGLE_API_KEY}"
| python3 -c "import sys,json; d=json.load(sys.stdin); print(json.dumps(d.get('values',[])))"
The README states that the skill remembers the Sheet ID throughout the conversation and describes local caching of sheet data, which creates session persistence of potentially sensitive document references and contents. In a data-access skill, retaining identifiers and cached spreadsheet data beyond the immediate request increases the chance of unintended reuse, stale-context access, or exposure to other local processes/users if permissions are weak.
### Google API Key (public sheet)
1. Go to [console.cloud.google.com](https://console.cloud.google.com)
2. Create a project → **APIs & Services → Library** → enable **Google Sheets API**
3. **APIs & Services → Credentials → Create Credentials → API Key**
4. Copy the key into your config
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
3. **IAM & Admin → Service Accounts → Create Service Account**
4. Go to the **Keys** tab → **Add Key → JSON** → download the file
5. Copy the file to `~/.openclaw/google-sa.json`
6. Fix permissions: `sudo chown 1000:1000 ~/.openclaw/google-sa.json`
7. Open your Google Sheet → **Share** → paste the `client_email` from the JSON file → Viewer
## Usage
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
3. **IAM & Admin → Service Accounts → Create Service Account**
4. Go to the **Keys** tab → **Add Key → JSON** → download the file
5. Copy the file to `~/.openclaw/google-sa.json`
6. Fix permissions: `sudo chown 1000:1000 ~/.openclaw/google-sa.json`
7. Open your Google Sheet → **Share** → paste the `client_email` from the JSON file → Viewer
## Usage
The activation criteria are broad enough to trigger on generic words like 'sheet' or 'spreadsheet' and casual requests such as 'check my sheet,' which can cause the skill to activate in contexts the user did not clearly intend. Because this skill can access Google Sheets data, over-triggering increases the risk of unnecessary data access, privacy exposure, and unintended use of configured credentials.
The instruction to run apt-get install -y python3 introduces package-management side effects unrelated to reading spreadsheet data. Allowing a skill to install software broadens its capabilities, can change the execution environment, and may be abused to trigger privileged or networked operations outside the user's intent.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
required: false
bins:
- python3
- curl
primaryEnv: GOOGLE_SERVICE_ACCOUNT_JSON
homepage: https://github.com/your-username/google-sheets-soha
repository: https://github.com/your-username/google-sheets-soha
The skill includes a global clear_cache() mode that wipes the entire sheets cache directory rather than only data for the active spreadsheet. This exceeds least-privilege for the stated task and could delete unrelated cached sheet data from other conversations or sheets, causing avoidable data loss or workflow disruption.
The manifest description emphasizes reading and analyzing Google Sheets data, which suggests a read-only analytics scope. However, the documented cache management flow includes clear_cache() operations that remove cached files and directories from local disk, which is behavior beyond pure read/analyze semantics.
No suspicious patterns detected.