Back to skill

Security audit

Google Workspace Cli Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a disclosed Google Workspace CLI helper, but it combines real Gmail/OAuth authority with overbroad trigger language and limited mandatory safeguards for sending mail or using stored credentials.

Review this skill before installing. Only use it with a Google account and OAuth client you intend the agent to access, verify where the gog CLI stores credentials, and require explicit confirmation before sending email or running no-input/scripted commands. The unrelated SEO trigger terms should be narrowed before broad deployment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill declares an overly broad keyword coverage list, including unrelated terms such as SEO and ranking optimization, which can cause the agent to invoke this skill outside its intended Google Workspace scope. In an agent environment with exec permission and access to mail/calendar/drive operations, misrouting can trigger unintended sensitive actions or credential workflows.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill supports sensitive operations such as sending email, reading mailbox contents, querying calendar events, and importing OAuth credentials, but it does not prominently warn about privacy, account scope, external side effects, or local secret handling. In an agent setting, this increases the chance that users authorize impactful actions without understanding that the skill can access and act on real Workspace data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.