Gws Reseller

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned, but it gives an agent Google Workspace reseller actions that can affect customer billing and service without clear approval safeguards.

Install only if you intend to let an agent help administer Google Workspace reseller customers and subscriptions. Verify the `gws` CLI and shared auth setup first, restrict credentials to the intended reseller account and scopes, and require explicit approval before any create, update, suspend, cancel, transfer, plan, seat, renewal, or paid-service action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents destructive subscription actions such as delete and suspend without any explicit warning about business impact, irreversibility, or the need for user confirmation. In a reseller context, these operations can disrupt customer billing and service availability, so presenting them as ordinary commands increases the risk of accidental harmful execution by an agent or user.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal