Back to skill

Security audit

Google Docs

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Google Docs automation skill, but it gives an agent direct document overwrite, deletion, replacement, and export powers without built-in confirmation or safety controls.

Review this before installing if the agent may access important Google Docs. Only use it with documents you are willing to let the agent modify, keep backups or version history available, and require explicit human approval before overwrite, delete, replace-all, or export operations. Protect MATON_API_KEY like a credential and consider pinning dependencies before deployment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Installation

Content
View full analysis
=2.28.0 ``` `SKILL.md:279-281`: ```bash # Setup pip install requests ``` `README.md:25-29`: ```bash 1. **Install dependencies**: ```bash pip install requests ``` ``` ### Technical Analysis The project specifies only a minimum version of `requests` and does not provide an exact version, lock file, or package integrity hashes. The installation documentation similarly directs users to install the latest version resolved by pip from the configured package index. Consequently, installations are not reproducible: the effective dependency can change without any modification to the audited project. This creates a supply-chain exposure if a future dependency release, transitive dependency, or configured package source is compromised. No evidence was found that the current `requests` package is malicious. The risk arises from accepting future, unreviewed dependency versions and trusting the environment's default package-index configuration without integrity verification. ### Attack Path 1. An attacker compromises a future dependency release, a transitive dependency, or a package index configured in the victim's pip environment. 2. A user follows the documented `pip install requests` instruction or installs from `requirements.txt`. 3. Pip resolves a version newer than the one originally reviewed because no upper or exact version constraint is present. 4. The compromised package executes installation-time or import-time code. 5. When `gdocs_driver.py` imports and uses the dependency, malicious code can run under the privileges of the invoking user. This path requires compromise or manipulation of the dependency distribution channel; the audited project does not itself retrieve or execute a se ...[truncated 691 chars]
Remediation
View remediation
``` 2. Generate and commit a lock file containing exact versions for all direct and transitive dependencies. 3. Record cryptographic hashes and require their verification during installation, for example: ```bash pip install --require-hashes -r requirements.txt ``` 4. Update `SKILL.md` and `README.md` so installation instructions use the locked, hash-verified dependency file instead of `pip install requests`. 5. Explicitly document the trusted package index and advise users to review pip configuration for unauthorized extra indexes or mirrors. 6. Establish a controlled dependency-update process that includes vulnerability scanning, release review, tests, and regenerated integrity hashes before accepting new versions. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tainted flow: 'MATON_API_KEY' from os.environ.get (line 45, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · gdocs_driver.py (reported line 113)May include surrounding context.

python
def list_connections():
    """列出所有 Google Docs 连接。"""
    resp = requests.get(
        f"{CTRL_BASE}/connections?app=google-docs&status=ACTIVE",
        headers={"Authorization": f"Bearer {MATON_API_KEY}"},
        verify=_SSL_VERIFY,

Tainted flow: 'MATON_API_KEY' from os.environ.get (line 45, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · gdocs_driver.py (reported line 124)May include surrounding context.

python
def create_connection():
    """创建新的 Google Docs OAuth 连接,返回授权 URL。"""
    resp = requests.post(
        f"{CTRL_BASE}/connections",
        headers={
            "Authorization": f"Bearer {MATON_API_KEY}",

Tainted flow: 'MATON_API_KEY' from os.environ.get (line 45, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · gdocs_driver.py (reported line 382)May include surrounding context.

python
f"?mimeType={urllib.parse.quote(mime)}"
    )

    resp = requests.get(
        export_url,
        headers={"Authorization": f"Bearer {MATON_API_KEY}"},
        verify=_SSL_VERIFY,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly advertises capabilities to clear/overwrite full document contents and export files to disk, but it does not warn that these actions are destructive or create local artifacts. In an agent-integrated context, ambiguous user prompts could cause unintended document modification or file writes, especially when the tool is framed as easy and fully automated.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill demonstrates capabilities requiring environment access, file output, and network requests, but it does not declare any explicit tool scope or allowed tools. This weakens policy enforcement and reviewability, increasing the chance that an agent can invoke broader capabilities than a user or platform expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents batchUpdate-based content modification features without caution about irreversible or bulk changes. In an agent context, this can normalize unsafe write operations and increase the likelihood of accidental mass edits to user documents without explicit confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The deleteContentRange example performs direct content deletion but provides no warning that it permanently removes document data. In an automated agent workflow, a user or model could invoke this pattern without appreciating its destructive effect, leading to data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented overwrite command implies replacement of the full document contents without a warning about destructive behavior. In an agent setting, concise CLI examples are likely to be copied directly, so omission of caution materially raises the risk of accidental data loss.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · gdocs_driver.py (reported line 124)May include surrounding context.

python
def create_connection():
    """创建新的 Google Docs OAuth 连接,返回授权 URL。"""
    resp = requests.post(
        f"{CTRL_BASE}/connections",
        headers={
            "Authorization": f"Bearer {MATON_API_KEY}",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The write command deletes the full document body and replaces it immediately, with no confirmation gate, dry-run mode, or revision precondition. In an agent setting, a mistaken instruction, wrong document ID, or prompt-injection-driven action could irreversibly destroy user content before the user notices.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

Most user-facing instructions and example invocations are presented only in Chinese, and the README does not indicate that other languages are supported or that Chinese is an optional locale. Under the language/locale policy, forcing or implying a single language without user opt-in can be a policy issue unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest and introductory description position this as a Google Docs skill for reading and writing Docs content. However, the documented implementation includes calls to the Google Drive API via a different gateway path to export files, which extends behavior beyond pure Docs API operations even though export is mentioned at a feature level.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file's natural-language interface, examples, help strings, and runtime messages are presented in Chinese only. That creates a language policy concern because the skill forces a specific language/locale without offering opt-in, fallback, or multilingual support.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as requests>=2.28.0, which allows any future version and does not guarantee a reproducible or reviewed install. This increases supply-chain risk and makes it possible to unintentionally pull a vulnerable or breaking release, especially significant in a skill that interacts with OAuth-authenticated Google Docs data over the network.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Because requests is not pinned, there is no way to verify whether installations will use a version affected by known advisories, including issues related to credential leakage and request handling. In the context of a Google Docs integration using managed OAuth, dependency uncertainty is more dangerous because the package may process authenticated HTTP traffic and sensitive document data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.