Gog Cli

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Google Workspace CLI skill, but it can act on live email, calendar, and spreadsheet data, so users should limit access and confirm writes.

Install only if you trust the gog CLI and are comfortable granting it access to your Google account. Use the narrowest Google services possible, test on non-critical spreadsheets first, and require explicit confirmation before any send, create, update, append, delete, or clear operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill includes data-modifying commands such as Sheets update, append, and clear, plus mail sending and event creation guidance, but provides only a brief generic confirmation note rather than explicit warnings about irreversible changes, targeting mistakes, or dry-run/safe usage patterns. In a tool that operates on live Google Workspace data, this increases the risk of accidental destructive actions or unauthorized modification if an agent uses the examples directly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal