Back to skill

Security audit

Manage Google Keep notes

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims for Google Keep, but its token setup asks users to handle sensitive Google authentication material in unsafe, under-scoped ways.

Install only if you are comfortable giving this skill read/write access to Google Keep notes and manually handling a reusable Google authentication token. Avoid pasting browser cookies or tokens into chats, logs, or shared terminals; restrict token.json permissions, review note IDs before archive/delete actions, and prefer a safer official OAuth flow if available.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:47
Finding

Unsafe Shell Interpolation Guidance for User-Controlled Note Names

Content
View full analysis
→ note_id 3. → gkeep.py get → show content 4. User: "Add milk to " 5. → gkeep.py list | grep → note_id 6. → gkeep.py add "milk" ``` ### Technical Analysis The documented workflow directs the agent to place a note name derived from the user's request into a shell pipeline involving `grep`. It does not require argument-array execution, robust quoting, an end-of-options marker, or validation of shell metacharacters. If an agent substitutes the supplied note name directly into the command, characters such as command substitutions, semicolons, pipes, or redirections may be interpreted by the shell rather than treated as literal search text. Although the Python CLI does not itself invoke a shell, the skill instructions establish an unsafe execution pattern that an agent may follow. ### Attack Path 1. An attacker requests access to a note whose alleged name contains shell syntax. 2. The agent follows the documented workflow and substitutes that value into `gkeep.py list | grep `. 3. The generated command is passed to a shell without safe argument separation. 4. The shell interprets the embedded syntax. 5. An attacker-selected local command executes with the same operating-system privileges as the agent process. Exploitation depends on the calling agent performing direct shell interpolation as suggested by the workflow. ### Impact Assessment Successful exploitation could permit arbitrary command execution under the account running the skill. This may expose local files, the Google Keep master token stored under `~/.config/gkeep/token.json`, environment variables, and other credentials available to the agent. It may also allow local file modification or execut ...[truncated 137 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate_token.py:13
Finding

Authentication Secrets Are Echoed, Printed, and Manually Stored Without Enforced Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unnecessary Third-Party Dependencies Expand the Supply-Chain Attack Surface

Content
View full analysis
=0.14.0 google google-auth-oauthlib google-api-python-client ``` The setup process installs these dependencies directly: ```bash pip install -r requirements.txt ``` ### Technical Analysis The requirement for `gkeepapi` uses an open-ended lower bound, allowing future releases to be installed without review. The other packages do not specify versions at all. No package hashes or reviewed lock file are supplied, so installation results may change over time. The audited project code imports `gkeepapi`, while `generate_token.py` imports `gpsoauth`. It does not directly import `google`, `google-auth-oauthlib`, or `google-api-python-client`. Installing packages that are not required by the code unnecessarily increases the number of publishers, artifacts, transitive dependencies, and package installation routines that must be trusted. There is no evidence that the currently named dependencies are intentionally malicious. The security issue is uncontrolled and unnecessarily broad supply-chain exposure. ### Attack Path 1. A user follows the setup instructions and executes `pip install -r requirements.txt`. 2. The package resolver selects the latest versions satisfying the broad or absent constraints. 3. A selected direct or transitive dependency has been compromised, maliciously updated, or changed incompatibly after the skill was reviewed. 4. Package build or installation logic executes during installation, or compromised code executes when the skill imports the package. 5. The malicious dependency obtains the permissions of the user performing installation or running the skill. ### Impact Assessment A compromised dependency may execute arbitrary code with the privileges of th ...[truncated 383 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README instructs users to obtain an OAuth token by opening browser developer tools, extracting a cookie/token value manually, and storing it in a local file. This bypasses standard OAuth handling, encourages unsafe credential extraction and persistence, and materially increases the risk of account compromise if the token is exposed, mishandled, or logged.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill behavior differs from its declared interface by using password or app-password based login and storing a master token rather than the stated OAuth model, while also exposing additional operations. Misrepresenting the authentication model is security-relevant because users may provide stronger credentials than expected and the stored token may have broader persistence or access than a scoped OAuth token.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding indicates the skill behavior differs from its declared interface by using password or app-password based login and storing a master token rather than the stated OAuth model, while also exposing additional operations. Misrepresenting the authentication model is security-relevant because users may provide stronger credentials than expected and the stored token may have broader persistence or access than a scoped OAuth token.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file describes a full natural-language flow for harvesting a browser-derived OAuth cookie token, exchanging it for another token, and then exposing the result for reuse. In the context of a note-management skill, this is especially dangerous because it bypasses normal safe auth UX and normalizes handling raw authentication artifacts that can grant account access.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

clawhub install gkeep-notes

text
```bash
sudo apt install python3-pip
sudo apt install python3.12-venv
python3 -m venv $HOME/.openclaw/workspace/skills/gkeep-notes/venv
source $HOME/.openclaw/workspace/skills/gkeep-notes/venv/bin/activate

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 12)May include surrounding context.

clawhub install gkeep-notes

text
```bash
sudo apt install python3-pip
sudo apt install python3.12-venv
python3 -m venv $HOME/.openclaw/workspace/skills/gkeep-notes/venv
source $HOME/.openclaw/workspace/skills/gkeep-notes/venv/bin/activate

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requests shell, environment, and file read/write capabilities through its setup and execution instructions but does not declare any tool scope restrictions. That increases the blast radius if the skill is invoked in an automated agent environment, because the agent may grant broader access than users expect and there is no explicit least-privilege boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises delete/trash and archive operations without any warning, confirmation pattern, or guidance to verify user intent. In an agent setting, ambiguous natural-language requests or mistaken note IDs could lead to unintended destructive changes to a user's notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation tells users to generate and place an OAuth token file without any privacy or security warning about handling credential material. That is risky because tokens stored in predictable local paths may be exposed to other tools, logs, backups, or users, enabling unauthorized access to the associated Google account data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script explicitly instructs the user to extract an oauth_token from browser cookies via developer tools and then submits it for token exchange. This creates a credential-harvesting workflow around highly sensitive authentication material, increasing the chance of account compromise, token theft, and misuse beyond the intended Keep integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script prints the resulting account token directly to stdout and suggests pasting it into a config file. Secrets displayed on screen can be captured in shell history, terminal logs, screen recordings, CI logs, or by shoulder surfing, making accidental disclosure likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The login flow persists a long-lived Google Keep master token to a predictable file on disk, and the CLI/documentation does not clearly warn users that sensitive credentials will be stored locally. Even though the file is chmodded to 0600, local malware, backups, shared home directories, or accidental exfiltration of dotfiles could expose the token and allow unauthorized access to the user's notes/account session.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

Using 'gkeepapi>=0.14.0' sets only a minimum version and still allows any newer release to be installed, so the environment is not reproducible. That expands the attack surface to future upstream versions and can introduce unreviewed security or behavioral changes into a note-management skill that handles user content and OAuth-related workflows.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
gkeepapi>=0.14.0
google 
google-auth-oauthlib 
google-api-python-client

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency 'google' is unpinned, so installs may resolve to different versions over time, reducing build reproducibility and increasing supply-chain risk if a bad or incompatible release is published. In Python, the 'google' package name is also broad and potentially confusing compared to the more specific Google client libraries, which can increase the chance of unintended package resolution.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
gkeepapi>=0.14.0
google 
google-auth-oauthlib 
google-api-python-client

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'google-auth-oauthlib' is unpinned, allowing future installs to pull newer releases without review. This creates a supply-chain and stability risk because a compromised, vulnerable, or breaking upstream release could be introduced into the environment unexpectedly.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
gkeepapi>=0.14.0
google 
google-auth-oauthlib 
google-api-python-client

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'google-api-python-client' is unpinned, which permits uncontrolled version drift across deployments. If an upstream release introduces a security issue or malicious code, the skill could consume it automatically during installation.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
gkeepapi>=0.14.0
google 
google-auth-oauthlib 
google-api-python-client

Static analysis

No suspicious patterns detected.