Back to skill

Security audit

Google Blogger

Security checks for vulnerabilities and agentic risk

Overview

The core Blogger CLI is recognizable, but the package also includes under-disclosed TechRex-specific scripts that can publish or overwrite posts and insert promotional content without adequate scoping or confirmation.

Install only after reviewing the TechRex-specific scripts. Prefer the main gblog.py commands with explicit blog and post IDs, and avoid running update-blogger-full.py or the generator scripts unless you first remove hard-coded paths, remove or intentionally keep the branding, preview changes, back up existing posts, and use a limited Blogger account or OAuth client.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/generate-smart-blogs.py:35
Finding

Generated blog posts are modified with undisclosed TechRex promotional content

Content
View full analysis

{title}

Category: {category} | Published: {date}

{embed_code} {body}

Tags: {tags_html}

🦖 Evolve or Get Extinct

Learn, Build, Launch — Without The Struggle. Subscribe for more AI tutorials!

Subscribe on YouTube →
''' ``` ### Technical Analysis Multiple content-generation scripts unconditionally append TechRex branding and a YouTube subscription link to generated HTML. The Skill's principal description presents it as a general Blogger management tool and does not clearly disclose that generators will insert promotional content into posts. Because the generated files can subsequently be sent to Blogger by the authenticated bulk-publishing and batch-update scripts, the ...[truncated 1177 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gblog.py:155
Finding

OAuth callback lacks state validation, enabling login CSRF and authorization-code substitution

Content
View full analysis
' '

Authentication Successful!

' '

You can close this window and return to the terminal.

' '' ) self.wfile.write(html.encode('utf-8')) server = HTTPServer(('localhost', 8085), CallbackHandler) print_info("Waiting for authorization... (Ctrl+C to cancel)") while not code: server.handle_request() server.server_close() # Exchange code for token token_data = urlencode({ 'code': code, 'client_id': client['client_id'], 'client_secret': client['client_secret'], 'redirect_uri': redirect_uri, 'grant_type': 'authorization_code' }).encode() req = Request('https://oauth2.googleapis.com/token', data=token_data, method='POST') req.add_header('Content-Type' ...[truncated 1963 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/update-blogger-full.py:14
Finding

Batch updater can overwrite the wrong Blogger posts without confirmation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:48
Finding

Documentation installs an unpinned third-party Python dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Bulk updates from hard-coded filesystem paths are inconsistent with a broadly scoped Blogger management CLI and create hidden coupling to local project data. That increases the chance of accidental modification or publication of unintended content from a specific workspace without clear user awareness.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

md
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

md
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 161)May include surrounding context.

md
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gblog.py (reported line 20)May include surrounding context.

python
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gblog.py (reported line 40)May include surrounding context.

python
Blogger API CLI for managing blog posts. Post, edit, delete, list, and monitor Blogger blogs.
  Use when the user wants to: (1) publish blog posts to Blogger, (2) edit existing blog posts,
  (3) list or search blog posts, (4) delete blog posts, (5) schedule posts, (6) monitor blog activity.
  Requires Google OAuth credentials in ~/.config/gblog/credentials.json
---

# gblog - Blogger CLI

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The script handles long-lived OAuth refresh tokens and access tokens from local storage, which are highly sensitive credentials that grant Blogger account access. While this is necessary for functionality, the code stores token material in plaintext JSON and does not protect against insecure pre-existing file permissions or use of a symlinked token path, increasing the risk of local credential theft on a shared or compromised system.

Content

Scanner excerpt · scripts/gblog.py (reported line 61)May include surrounding context.

python
os.chmod(TOKEN_FILE, 0o600)

def refresh_access_token():
    """Refresh access token using refresh token"""
    token = load_token()
    if not token or 'refresh_token' not in token:
        return None

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Retrieving and using access tokens from a plaintext local token store exposes sensitive bearer credentials that can be reused by anyone who obtains the file. In this Blogger-management context, theft of the token could allow unauthorized reading, posting, editing, or deletion of blog content until the token expires or is revoked, and refresh tokens can extend that access.

Content

Scanner excerpt · scripts/gblog.py (reported line 90)May include surrounding context.

python
return None

def get_access_token():
    """Get valid access token"""
    token = load_token()
    if not token:
        print_error("Not authenticated. Run: gblog auth")

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a CLI for managing Blogger posts via the Blogger API, including posting, editing, deleting, listing, scheduling, and monitoring blogs. This file instead reads a local posts.json dataset, fetches YouTube transcripts, and generates standalone HTML files in a local workspace, which is a different content-production workflow rather than Blogger management.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script is materially inconsistent with the declared skill purpose: instead of using Blogger APIs, it reads a local posts.json file and mass-generates HTML files under a separate TechRex website workspace. That mismatch is dangerous because users invoking a Blogger-management skill could unknowingly execute unrelated filesystem-modifying logic, enabling deceptive repurposing of the skill and unintended writes to local project content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script’s behavior materially diverges from the skill’s declared purpose of managing Blogger posts via the Blogger API: it fetches YouTube transcripts, generates HTML via an external tool, and writes files into a local workspace. Capability drift is dangerous because users may grant trust and permissions based on the manifest, while the code performs unrelated content harvesting and local file generation with no Blogger API interaction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.