Back to skill

Security audit

Sync Adapter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Google Sheets sync helper, but it relies on a local service-account credential and recurring scheduled writes that users should scope carefully.

Before installing, confirm the service account is least-privilege, the spreadsheet ID is the intended destination, cron scheduling is desired, and the source Markdown files are narrowly defined. Avoid logging, copying, or exposing the service-account JSON.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The authentication section instructs the agent to use a service account to sign JWTs and exchange them for access tokens to a specific Google Sheets target. While this is framed as intended functionality, it is still credential-access behavior, and in this context it is dangerous because the skill also provides the credential location and a live spreadsheet identifier, enabling direct access to external data if abused.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
## Authentication

- Service account: `/home/hobopi/.openclaw/secrets/google-service-account.json`
- JWT flow: sign with RSA256, exchange for access token
- Sheet API: `https://sheets.googleapis.com/v4/spreadsheets/{id}`
- Spreadsheet ID: `1Ikbydh-Xzc6F3pk1Q5lbCTbdEERSb4Hq8obzbABVZbU`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill embeds a concrete filesystem path to Google service-account credentials, disclosing where sensitive authentication material resides on the host. In an agent environment with read/exec capabilities, this materially lowers the barrier for accidental misuse or targeted credential theft by other skills, prompts, or operators.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.