Back to skill

Security audit

Gmail Gog Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for setting up Gmail access, but it asks users to install an unverified system-wide executable and handle Gmail credentials in ways that deserve review before use.

Review before installing. Use a dedicated Gmail account, verify the Gog release with a trusted checksum or signature, prefer a user-local install path, avoid putting the keyring password in shell history or shared environments, unset it after use, and understand that the configured OAuth access can persist until revoked.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unverified Third-Party Executable Download and System-Wide Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35-39
Vulnerability Type: Unverified third-party dependency installation
Risk Level: Medium

bash
# Install Gog from latest release
cd /tmp
curl -L -o gogcli_0.12.0_linux_amd64.tar.gz https://github.com/steipete/gogcli/releases/download/v0.12.0/gogcli_0.12.0_linux_amd64.tar.gz
tar -xzf gogcli_0.12.0_linux_amd64.tar.gz
install -m 0755 gog /usr/local/bin/gog

Technical Analysis

The Skill downloads a precompiled executable archive from a third-party GitHub repository, extracts it, and installs the resulting executable into /usr/local/bin. Although the release version is pinned to v0.12.0, the instructions do not verify a cryptographic checksum or trusted release signature. Version pinning alone does not establish artifact integrity or publisher authenticity.

The process also operates directly in the shared /tmp directory rather than a newly created private temporary directory. The predictable archive filename and extracted executable name increase exposure to local file-race or replacement attacks between download, extraction, and installation.

Installation into /usr/local/bin normally requires elevated privileges and places the executable on the system-wide command path. This exceeds the minimum privileges necessary to provide Gmail access when a user-local installation directory could be used instead.

The risk is amplified because the installed program subsequently processes Google OAuth client material, authorization callbacks, stored tokens, the keyring password, and Gmail data.

Attack Path

Supply-chain attack path:

  1. An attacker compromises the referenced GitHub account, release artifact, or upstream build and publishes a malicious archive at the pinned release URL.
  2. A user follows the Skill instructions and downloads the archive without validating a checksum or signature.
  3. The malicious gog executable is extrac ...[truncated 1543 chars]
Remediation
View remediation

Remediation Suggestions

  1. Publish and pin a trusted SHA-256 digest for the exact archive, then verify it before extraction:
    bash
    printf '%s  %s\n' 'EXPECTED_SHA256' 'gogcli_0.12.0_linux_amd64.tar.gz' | sha256sum --check -
    
  2. Verify a cryptographic release signature from a separately established trusted publisher key when signed releases are available.
  3. Prefer an official, organization-controlled package repository or other authenticated distribution channel.
  4. Use a private temporary directory created with mktemp -d, apply restrictive permissions, and remove it after installation.
  5. Inspect archive entries before extraction and reject absolute paths, parent-directory traversal, links, and unexpected files.
  6. Avoid system-wide installation unless it is operationally required. Install the verified executable into a user-owned directory such as ~/.local/bin to avoid unnecessary privilege elevation.
  7. If system-wide installation is required, separate artifact verification from the narrowly scoped privileged installation step and install only the exact verified file.
  8. Document the binary's publisher, expected digest, required Gmail OAuth scopes, and update procedure so future upgrades do not silently reintroduce unverified downloads.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The documented use of a keyring password in an exported environment variable creates credential-handling risk even if intended for convenience. If an attacker with local or CI/container visibility can read the variable, they may unlock persisted Gog authentication material and gain mailbox access.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

2. Authenticate the Gmail account

bash
export GOG_KEYRING_PASSWORD='your-keyring-password'
gog auth add agent@gmail.com --services gmail --manual
  • Open the provided auth URL in browser

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The documented use of a keyring password in an exported environment variable creates credential-handling risk even if intended for convenience. If an attacker with local or CI/container visibility can read the variable, they may unlock persisted Gog authentication material and gain mailbox access.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

2. Authenticate the Gmail account

bash
export GOG_KEYRING_PASSWORD='your-keyring-password'
gog auth add agent@gmail.com --services gmail --manual
  • Open the provided auth URL in browser

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description at L003 limits the skill to Gog CLI setup and mailbox authentication. However, the documented scope expands into Google Cloud OAuth client administration (L024, L028-L032) and mailbox content modification via gog gmail messages modify (L085-L087), which goes beyond simple setup/authentication.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Adding OAuth clients and test users in Google Cloud Console is an administrative capability outside the immediate task of authenticating a mailbox with an already-installed CLI. While related, it broadens the skill into cloud application configuration rather than just Gog/Gmail setup.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
## Prerequisites

### 1. Google Cloud OAuth client
- Create a **Desktop app** OAuth client in Google Cloud Console
- Enable **Gmail API**
- Add target Gmail address as a **test user** in OAuth consent screen
- Download the client JSON file

Static analysis

No suspicious patterns detected.