Recipe Organize Drive Folder

Security checks across malware telemetry and agentic risk

Overview

This is a simple Google Drive organization recipe that can move files, so users should verify the target files and folders before running it.

Install only if you intend to let an agent organize Google Drive content. Before running the move command, confirm the active gws account, list the files involved, and verify the FILE_ID, FOLDER_ID, and OLD_PARENT_ID values so the wrong files are not moved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to move existing Google Drive files by changing parent folders, which modifies user data organization and can disrupt workflows if done without explicit confirmation or safeguards. In a recipe-style skill, these commands are presented as direct steps with placeholder IDs but no warning about side effects, validation of targets, or confirmation before altering existing file locations.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal