Back to skill

Security audit

Gws Drive

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Google Drive CLI reference skill with powerful but disclosed Drive management operations.

Install only if you want an agent to operate Google Drive through the gws CLI. Before allowing mutating actions, review the exact target file or shared drive, requested permission changes, deletion operations, and active Google auth scopes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill enumerates destructive and access-changing Drive operations such as file deletion, revision deletion, permission changes, and access proposal resolution without prominent safety guidance about irreversibility, data loss, or sharing consequences. In an agent setting, this increases the chance of accidental harmful actions by users or downstream automation, especially because the document reads like an operational menu rather than a guarded interface.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.