Back to skill

Security audit

gogcli - Google Workspace CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Google Workspace CLI helper, but it asks users to install mutable third-party code and grant persistent access to sensitive Google account data with limited scoping or consent guidance.

Review this skill carefully before installing. Use a dedicated or least-privilege Google account where possible, enable only the APIs you need, avoid sudo make install unless you have inspected the upstream project, and know how to revoke the OAuth credentials stored under ~/.config/gog/.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Third-Party Dependency Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18-33
Vulnerability Type: Supply-chain risk from mutable, unverified third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
brew install steipete/tap/gogcli
bash
# 1. Clone repository
git clone https://github.com/steipete/gogcli.git

# 2. Navigate to directory
cd gogcli

# 3. Build
make

# 4. (Optional) Make available globally
sudo make install

Technical Analysis

Both documented installation methods retrieve mutable third-party content without pinning a reviewed version, release tag, or commit hash. The instructions also do not require verification of a checksum or cryptographic signature.

The source installation path immediately executes repository-controlled build instructions through make. The optional sudo make install command subsequently executes repository-controlled Makefile targets with root privileges. The Homebrew command similarly relies on the current contents of a third-party tap without identifying a known-good package version.

Consequently, the code executed during installation may differ from the content that was previously reviewed. Exploitation requires compromise or malicious modification of an upstream repository, release process, maintainer account, Homebrew tap, or another relevant distribution component.

Attack Path

  1. An attacker compromises the upstream GitHub repository, maintainer account, Homebrew tap, or release infrastructure.
  2. The attacker modifies the repository build logic or package formula to execute malicious commands.
  3. A user follows the Skill instructions and retrieves the mutable upstream content using brew install or git clone.
  4. The user executes the malicious content through make or the package installation process.
  5. If the user runs sudo make install, repository-controlled commands may execute with root privileges.
  6. Malicious code ...[truncated 1008 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin installation instructions to a reviewed release version and, for source builds, an immutable commit hash.
  2. Publish expected SHA-256 or stronger checksums for downloaded artifacts and require users to verify them before execution.
  3. Prefer signed releases and document verification of the maintainer's cryptographic signature.
  4. Avoid tracking a mutable default branch in installation instructions. Use a command that checks out the explicitly reviewed tag or commit before running any build step.
  5. Replace sudo make install with a user-scoped installation directory or a reviewed, signed package artifact whenever possible.
  6. If privileged installation remains necessary, instruct users to inspect the Makefile and installation target before invoking it with sudo.
  7. Pin the Homebrew formula version where supported and document the trusted tap and integrity-verification process.
  8. Document the minimum required OAuth scopes and advise users to grant only those scopes. Provide token revocation and credential-rotation instructions for suspected compromise.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's invocation description is extremely broad ('Use when user asks to interact with Google services'), which can cause the agent to trigger this skill for many ordinary requests involving sensitive Google Workspace data. In context, the tool can access Gmail, Drive, Contacts, Calendar, and other private resources, so overbroad routing increases the chance of unnecessary or unintended remote actions against a user's account.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

make

4. (Optional) Make available globally

sudo make install

text

## First Time Setup

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation describes authenticating a Google account and performing actions across email, files, contacts, calendar, and other services, but it does not warn about the sensitivity of account-wide access or the risk of remote, potentially irreversible actions. Because this skill enables access to highly sensitive personal and organizational data, omission of privacy and consent guidance makes accidental misuse more likely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The setup flow instructs users to create OAuth client credentials and authenticate an account, with credentials stored locally in a persistent configuration directory. In context, persistent Google OAuth tokens materially increase exposure if the host or account is later compromised, especially because the skill spans multiple sensitive Workspace services.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
**Step 1: Get OAuth Client Credentials**
1. Go to Google Cloud Console APIs & Services
2. Create project or use existing one
3. Go to OAuth consent screen
4. Create OAuth 2.0 client with these settings:
   - Application type: "Desktop app"

Static analysis

No suspicious patterns detected.