Back to skill

Security audit

Google Workspace

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but it asks users to install a mutable unverified binary and recommends weakening Google Advanced Protection during OAuth setup.

Review this skill before installing. Use a pinned release and verify the SHA-256 checksum or signature before placing the binary in ~/.openclaw/bin. Do not disable Google Advanced Protection for a primary account; use an administrator-approved OAuth client or a dedicated least-privilege Google account. Keep readwrite modes off unless you explicitly need them, and remember that command output may contain private email, contact, calendar, Drive, Docs, or Sheets data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:30
Finding

Release Binary Is Downloaded and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:30-35
Vulnerability Type: Remote payload retrieval without checksum or signature verification
Risk Level: Medium

Vulnerable Code:

bash
TAG=$(curl -fsSL "https://api.github.com/repos/PanthroCorp-Limited/openclaw-skills/releases" \
  | grep -o '"tag_name":"google-workspace/v[^"]*"' | head -1 | cut -d'"' -f4)
VERSION=${TAG#google-workspace/v}
curl -fsSL "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/${TAG}/google-workspace_${VERSION}_linux_arm64.tar.gz" \
  | tar -xz -C ~/.openclaw/bin/ google-workspace
chmod +x ~/.openclaw/bin/google-workspace

Technical Analysis

The installation procedure dynamically selects the latest GitHub release and streams its archive directly into tar. The installed file is then marked executable without validating a pinned cryptographic digest or trusted signature.

HTTPS protects the download in transit but does not protect against compromise of the publisher's GitHub account, release workflow, repository, or release artifacts. Because the selected tag is not pinned, the effective executable can change after the Skill has been reviewed.

The repository includes SHA-256 checksums in dist/checksums.txt, including a checksum for the Linux ARM64 archive, but the documented installation flow does not use them. This behavior is security-sensitive because the resulting executable runs in an environment containing GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, and GOOGLE_WORKSPACE_TOKEN_KEY. It can also read and decrypt the stored OAuth token when invoked with those environment variables.

Attack Path

  1. An attacker compromises the GitHub release account, repository workflow, or artifact publication process.
  2. The attacker publishes or replaces the release archive selected by the dynamic tag lookup.
  3. An operator follows the installation instructions.
  4. curl downloads the modified arch ...[truncated 1189 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin installation instructions to a specific reviewed version rather than dynamically selecting the latest release.
  2. Download the archive and checksum manifest to temporary files instead of streaming the archive directly into tar.
  3. Verify the archive using a pinned SHA-256 digest before extraction:
    bash
    VERSION="0.5.2"
    ARCHIVE="google-workspace_${VERSION}_linux_arm64.tar.gz"
    curl -fL -o "$ARCHIVE" \
      "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/google-workspace/v${VERSION}/${ARCHIVE}"
    echo "c1d430a17457f9ce0d1f9c38eac5d816652ac9bd1150a4ee4c21c2b642e245ac  ${ARCHIVE}" \
      | sha256sum -c -
    tar -xzf "$ARCHIVE" -C ~/.openclaw/bin/ google-workspace
    chmod 0755 ~/.openclaw/bin/google-workspace
    
  4. Prefer cryptographically signed releases, such as Sigstore/Cosign attestations, and verify the expected publisher identity and build provenance.
  5. Extract to a temporary directory, validate the expected file type and name, and move the verified binary atomically into place.
  6. Run the binary under a dedicated least-privilege account and expose credentials only for commands that require them.

other

Warning
Location
SKILL.md:200
Finding

Authentication Guidance Recommends Disabling Google Advanced Protection

Content
View full analysis

Vulnerability Details

File Locations: SKILL.md:200-207, README.md:109
Vulnerability Type: Security control downgrade through operational instructions
Risk Level: Medium

Risky Instruction:

markdown
Check if the token is valid:
text
google-workspace auth status
markdown
If the token has expired, ask the operator to re-authenticate by running `google-workspace auth login` on the host.

If authentication fails with `Error 400: policy_enforced`, the operator's Google account likely has Advanced Protection enabled. They will need to temporarily unenroll, complete the OAuth flow, then re-enroll. The refresh token persists across sessions.

Technical Analysis

The Skill instructs users to temporarily unenroll from Google Advanced Protection when OAuth authorization is blocked. Advanced Protection is an account-level defense intended to provide stronger resistance to phishing, account takeover, and unauthorized third-party application access.

Disabling that protection is not technically necessary to implement the Skill's declared Google Workspace functionality. The underlying compatibility problem should instead be resolved through an approved OAuth application, an appropriate organizational policy, or a dedicated account whose security policy permits the application.

Re-enrolling after OAuth authorization does not eliminate threats that may have occurred during the reduced-protection period. It also does not necessarily revoke refresh tokens or other access established while protection was disabled.

Attack Path

  1. An operator attempts to authorize the Skill and receives Error 400: policy_enforced.
  2. The operator follows the Skill instructions and unenrolls the Google account from Advanced Protection.
  3. During the reduced-protection window, the account becomes more exposed to credential phishing, session theft, malicious application authorization, or other account-ta ...[truncated 1235 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all recommendations to disable or temporarily unenroll from Google Advanced Protection.
  2. Replace the guidance with instructions to use a verified or administrator-approved OAuth application compatible with the account's security policy.
  3. For Google Workspace organizations, document the appropriate administrator approval or application allowlisting process.
  4. Recommend a dedicated, least-privilege Google account when the primary protected account cannot authorize the application.
  5. Treat policy_enforced as a hard authorization failure and do not encourage bypassing the policy:
    text
    Authentication was blocked by the account's security policy. Do not disable
    Advanced Protection. Use an administrator-approved OAuth client or a dedicated
    least-privilege account whose policy permits this application.
    
  6. If the application is intended for broader use, complete Google's applicable OAuth verification and security assessment requirements.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README explicitly instructs operators to temporarily disable Google Advanced Protection in order to complete OAuth authentication. This weakens an account-level security control protecting against phishing and unauthorized OAuth app access, and normalizes bypassing a strong defense for convenience. In the context of an agent skill that accesses sensitive Gmail, Drive, Contacts, and Calendar data, encouraging users to lower account protections materially increases the risk of account compromise and overbroad data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a multi-service Google Workspace skill spanning Gmail, Contacts, Calendar, Drive, Docs, and Sheets. However, this code chunk only exposes Gmail functionality, and even that is limited to read-only operations such as search, read, list labels, and inspect threads. There is no evidence in this chunk of Contacts, Calendar, Drive, Docs, or Sheets access. That makes the declared purpose materially broader than the actual behavior shown here. The OAuth/config/token handling is supporting infrastructure and not itself a mismatch, but the core represented capability does not align with the supplied implementation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description suggests a Google Workspace integration skill exposing capabilities for Gmail, Contacts, Calendar, Drive, Docs, and Sheets. However, the supplied code chunk only contains internal crypto helpers for symmetric encryption and decryption, likely to protect secrets or tokens. While such crypto may support a Workspace integration internally, this chunk’s actual behavior does not itself provide or implement the declared end-user/service capabilities. Therefore, the code’s primary purpose is materially different from the declared purpose, making this a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description suggests Google Workspace service integrations (Gmail, Contacts, Calendar, Drive, Docs, Sheets). However, the actual code chunk contains only unit tests for a crypto module and does not interact with any Google services, agent triggers, APIs, or related resources. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description claims a broader Google workspace integration spanning Gmail, Contacts, Calendar, Drive, Docs, and Sheets. The supplied code only implements Gmail functionality, and specifically only read-only Gmail operations. There is no evidence in this chunk of Contacts, Calendar, Drive, Docs, or Sheets access. This is a description-behavior mismatch because the declared purpose materially overstates the capabilities represented by the provided code chunk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 77)May include surrounding context.

md
### 4. Deploy

Merge the Terraform changes to `main`. The deploy workflow will:
- Create SSM parameters for the three secrets
- Update the `.env` file on the instance with `GOOGLE_WORKSPACE_TOKEN_KEY`, `GOOGLE_CLIENT_ID`, and `GOOGLE_CLIENT_SECRET`
- Create the `config/credentials/google-workspace/` directory

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 87)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-google-workspace

6. Configure scopes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 93)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-google-workspace

6. Configure scopes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 100)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-google-workspace

6. Configure scopes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 114)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-google-workspace

6. Configure scopes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 115)May include surrounding context.

bash
ssh -i ~/.ssh/openclaw-operator ubuntu@<domain>
sudo -u openclaw docker exec -it openclaw-gateway clawhub install panthrocorp-google-workspace

6. Configure scopes

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares required environment variables and provides installation instructions for a network-capable binary, but it does not declare an explicit tool/permission scope. In an agent environment, missing scope declarations can cause the agent or operator to underestimate that the skill can access secrets, write binaries, and make outbound requests, increasing the risk of over-privileged use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The installation instructions download and extract an executable from remote GitHub endpoints directly into the agent's binary path using curl piped to tar, without any checksum or signature verification. This creates a supply-chain risk: if the release, repository, network path, or account is compromised, an operator could install a malicious binary with the skill's expected privileges.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

Download the latest release binary for linux/arm64 and install to ~/.openclaw/bin/:

bash
TAG=$(curl -fsSL "https://api.github.com/repos/PanthroCorp-Limited/openclaw-skills/releases" \
  | grep -o '"tag_name":"google-workspace/v[^"]*"' | head -1 | cut -d'"' -f4)
VERSION=${TAG#google-workspace/v}
curl -fsSL "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/${TAG}/google-workspace_${VERSION}_linux_arm64.tar.gz" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs a destructive operation by deleting a calendar event via the Google Calendar API, but there is no confirmation prompt or pre-action user-facing warning before the deletion executes. Printing "Event deleted." afterward does not disclose the risk in advance, so users are not warned before an irreversible change to their calendar data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command performs a network-backed read of Google Contacts data and immediately outputs the returned contact records. While the command is labeled read-only, this code path contains no prompt, warning, or explicit disclosure that personally identifiable contact data will be fetched and displayed to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The search command sends the provided query to Google Contacts and prints the results, but there is no warning, prompt, or inline disclosure about the external network call or the fact that contact data may be returned. For privacy-sensitive address book data, some visible disclosure is expected unless documented elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code retrieves an individual contact from Google Contacts and prints the full record as JSON. There is no visible user-facing warning in this file that personally identifiable information may be fetched from a remote service and displayed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level Drive command is explicitly described as 'Read-only Google Drive operations', but the file also registers write-capable subcommands that add comments and replies. This mismatch can mislead users, reviewers, or higher-level agents into invoking the skill under a false read-only assumption, resulting in unintended modification of Drive resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The read command fetches a Gmail message and immediately prints the full JSON payload, which may include sensitive message content and metadata. There is no confirmation prompt, warning text, or disclosure in this file that reading and displaying mailbox contents may expose private data in terminal logs or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The threads command prints either a full thread object or thread search results as JSON. For full thread reads in particular, this can expose private email content and associated metadata, yet the file provides no user-facing warning or confirmation about that disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The labels command prints mailbox label information directly to stdout. Although less sensitive than full message bodies, this still exposes user mailbox metadata without any explicit warning or disclosure in the command output or help text.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The functions on L49-L58 read credential-related environment variables, including a token key, client ID, and client secret. While the code is simple, this file provides no user-facing warning, log message, prompt, or explanatory comment that credentials will be sourced from environment variables.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The Save function creates a directory and writes config.json to disk, which is a safety-relevant file modification. While the function has a brief developer comment, there is no user-facing prompt, logging, or disclosure in this file indicating that configuration will be persisted on disk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The type-level documentation frames this client as a limited read-only contacts accessor, and the list/search methods only expose names, email addresses, phone numbers, and organizations. However, GetContact additionally requests biographies at L64, expanding data access beyond the fields implied by the surrounding documentation and comments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.