Back to skill

Security audit

命令行工具

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Google Workspace command-line helper, but it asks for broad account access and includes write/delete/export workflows with uneven scoping and disclosure.

Install only if you intend to let an agent operate a real Google Workspace CLI. Authorize the minimum Google services needed, avoid --no-input for send/write/delete/export actions unless the workflow is tightly controlled, and store exported mail, contacts, docs, and sheets data in protected locations with clear retention rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

text
配置后需重启会话或开启新终端生效。API Key应妥善保管,避免泄露到版本控制系统.
## 能力清单
- OAuth 凭证管理:导入 `client_secret.json`、添加多服务授权账户、列出已授权账户
- Gmail:按 Gmail 搜索语法检索邮件(`newer_than:`、`from:`、`has:attachment` 等)、发送邮件
- Calendar:按时间范围查询日历事件,支持 ISO8601 时间区间
- Drive:按查询语法检索文件,支持 `--max` 限制返回数量

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

text
配置后需重启会话或开启新终端生效。API Key应妥善保管,避免泄露到版本控制系统.
## 能力清单
- OAuth 凭证管理:导入 `client_secret.json`、添加多服务授权账户、列出已授权账户
- Gmail:按 Gmail 搜索语法检索邮件(`newer_than:`、`from:`、`has:attachment` 等)、发送邮件
- Calendar:按时间范围查询日历事件,支持 ISO8601 时间区间
- Drive:按查询语法检索文件,支持 `--max` 限制返回数量

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

text
配置后需重启会话或开启新终端生效。API Key应妥善保管,避免泄露到版本控制系统.
## 能力清单
- OAuth 凭证管理:导入 `client_secret.json`、添加多服务授权账户、列出已授权账户
- Gmail:按 Gmail 搜索语法检索邮件(`newer_than:`、`from:`、`has:attachment` 等)、发送邮件
- Calendar:按时间范围查询日历事件,支持 ISO8601 时间区间
- Drive:按查询语法检索文件,支持 `--max` 限制返回数量

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

text
配置后需重启会话或开启新终端生效。API Key应妥善保管,避免泄露到版本控制系统.
## 能力清单
- OAuth 凭证管理:导入 `client_secret.json`、添加多服务授权账户、列出已授权账户
- Gmail:按 Gmail 搜索语法检索邮件(`newer_than:`、`from:`、`has:attachment` 等)、发送邮件
- Calendar:按时间范围查询日历事件,支持 ISO8601 时间区间
- Drive:按查询语法检索文件,支持 `--max` 限制返回数量

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

text
配置后需重启会话或开启新终端生效。API Key应妥善保管,避免泄露到版本控制系统.
## 能力清单
- OAuth 凭证管理:导入 `client_secret.json`、添加多服务授权账户、列出已授权账户
- Gmail:按 Gmail 搜索语法检索邮件(`newer_than:`、`from:`、`has:attachment` 等)、发送邮件
- Calendar:按时间范围查询日历事件,支持 ISO8601 时间区间
- Drive:按查询语法检索文件,支持 `--max` 限制返回数量

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is extremely broad, covering generic productivity, automation, batch processing, and workflow optimization scenarios. In a skill with exec, file access, and Google Workspace reach, such vague invocation criteria can cause over-triggering on unrelated requests, leading the agent to access data or run commands more often than necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Claiming the tool 'automatically recognizes user needs' without defining boundaries encourages autonomous invocation beyond clearly authorized tasks. In the context of broad Google Workspace access plus execution tools, this increases the risk of unintended access to mail, documents, contacts, or local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The examples encourage exporting and locally archiving Google Workspace data, including emails and documents, without placing a privacy or retention warning directly in those workflow sections. That normalization can lead users or agents to persist sensitive workspace data to local storage or logs without considering confidentiality, retention, or access controls.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata enables exec while the documentation later classifies the skill as pure Markdown/MD-only. This mismatch can mislead an agent or reviewer about the actual execution surface, causing command-capable skills to be invoked under weaker scrutiny and increasing the chance of unintended command execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

The boundary section tries to narrowly define supported operations, but the surrounding documentation mixes generic automation claims and multiple write-capable operations such as Gmail send and Sheets update/append/clear. This creates intent ambiguity, and specifically the '需人工确认或调用 Calendar API' phrasing at L341 conflicts with the overall framing that gog is the unified API wrapper for these services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.