Back to skill

Security audit

Google Workspace

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly described Google Workspace operator that uses OAuth-enabled tools for mail, calendar, Drive, Docs, Sheets, and Slides, with sensitive capabilities disclosed in the instructions.

Install only if you want the agent to operate on your Google account. Review the OAuth scopes and token storage path, and be careful with requests that send email, share Drive files, trash files or messages, or delete calendar events.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill exposes broad access to sensitive Google Workspace data and includes high-impact actions such as sending email, sharing Drive files, and deleting or trashing content, but the top-level description does not clearly warn users about privacy exposure or destructive side effects. In an operator-facing skill, that omission increases the chance of accidental misuse because users may invoke it without realizing it can read across mail, files, calendars, and shared content or perform irreversible-looking actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.