sdfsdfsd

Security checks across malware telemetry and agentic risk

Overview

This skill is a Google Workspace command helper, but it combines broad account access with mutable external instructions and limited safety guidance for write actions.

Install only if you are comfortable giving this CLI access to real Google Workspace data. Review the external instructions manually instead of letting an agent treat them as trusted, use the narrowest OAuth scopes and a low-privilege account where possible, protect client_secret.json and token files, and require explicit confirmation before sending email or changing, appending, clearing, copying, or exporting Workspace content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill exposes write and destructive operations such as Sheets update, append, and clear, but only gives a generic confirmation warning for mail and calendar actions. In an agent context, presenting these commands without explicit per-command safety guidance increases the risk of accidental data modification or deletion in Google Workspace resources.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal