Credential Access
- Category
- Privilege Escalation
- Confidence
- 82% confidence
- Finding
The documentation identifies a secrets directory containing shared OAuth client credentials and per-account refresh tokens, which are highly sensitive and enable persistent access to Gmail accounts if exposed. In a skill designed to manage multiple accounts from one project, compromise of these files could grant broad unauthorized mailbox access across accounts.
- Content
text secrets/inbox/ client_secret.json — OAuth 2.0 Desktop client credentials (shared) accounts.json — {"account@gmail.com": {"label": ..., "token_file": "token-..."}} token-account-at-gmail-dot-com.json — per-account OAuth token
