T03 · Remote Payload Retrieval and Execution
- Location
scripts/onedrive-setup.sh:28- Finding
Privileged Execution of an Unpinned Remote Installation Script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill provides real OneDrive management features, but it also uses broad Microsoft Graph access and includes under-disclosed host and token-handling risks.
Review before installing. Use this only if you need broad OneDrive and SharePoint write, delete, and sharing automation. Prefer reduced Microsoft Graph scopes, a dedicated account, and secure token storage. Avoid the bootstrap script on shared or production hosts, do not set ONEDRIVE_GRAPH_BASE with real tokens, and do not print or pass live access or refresh tokens in logged shells.
scripts/onedrive-setup.sh:28Privileged Execution of an Unpinned Remote Installation Script
scripts/onedrive-files.sh:11Bearer Token Exfiltration Through an Unvalidated Graph API Base URL
scripts/onedrive-bootstrap.sh:46Bootstrap Performs Unnecessary Host-Wide Process, Permission, and Shell-Profile Changes
scripts/onedrive-bootstrap.sh:120Predictable Temporary Files Enable Symlink Overwrite Attacks and Metadata Leakage
scripts/onedrive-token.sh:107OAuth Access and Refresh Tokens Are Passed Through Command-Line Arguments
scripts/onedrive-setup.sh:14Unconditional Default OAuth Scopes Exceed Least-Privilege Requirements
The skill presents itself as file management but also includes raw access-token display, local credential persistence, and user-profile retrieval via /me. These are materially different from ordinary file operations and increase the chance of credential misuse or unintended data exposure under the guise of a benign storage skill.
The skill presents itself as file management but also includes raw access-token display, local credential persistence, and user-profile retrieval via /me. These are materially different from ordinary file operations and increase the chance of credential misuse or unintended data exposure under the guise of a benign storage skill.
A command that prints the raw access token to stdout creates immediate leakage risk via terminal scrollback, shell history capture, logging wrappers, CI output, or clipboard mishandling. Since bearer tokens are usable as-is, anyone who obtains the printed value can act as the user until expiry, and potentially longer if combined with refresh-token workflows.
./scripts/onedrive-token.sh refresh # Refresh expired token
./scripts/onedrive-token.sh test # Test connection
./scripts/onedrive-token.sh get # Print access token
./scripts/onedrive-token.sh info # Show token info / expiry
./scripts/onedrive-token.sh me # Show signed-in user
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Access tokens expire after ~1 hour. Refresh with:
./scripts/onedrive-token.sh refresh
The skill explicitly stores OAuth tokens and client secrets in local files, which are highly sensitive credentials. If those files are exposed through backups, misconfigured permissions, malware, or accidental disclosure, an attacker could gain persistent access to OneDrive and SharePoint data under broad delegated scopes.
## Files
- `~/.onedrive-mcp/config.json` — Client ID, secret, tenant, scopes
- `~/.onedrive-mcp/credentials.json` — OAuth tokens (access + refresh)
Both files are `chmod 600`, directory `700`. Never commit them.
The 'Bring Your Own Access Token' section encourages use of externally obtained Graph tokens inside the skill. That is not inherently malicious, but in this context it normalizes handling raw bearer tokens and increases the likelihood of unsafe copy/paste, reuse of overprivileged tokens, and accidental disclosure.
Discover drive IDs with `./scripts/onedrive-files.sh drives`.
## Bring Your Own Access Token
If you already have a Microsoft Graph access token (from another app / Postman / MSAL / etc.), three options:
Documenting environment-variable injection of access tokens can expose credentials through process listings, shell history, crash dumps, debug tooling, or inherited environments. In a cloud-file-management skill with broad scopes, that can translate directly into unauthorized read/write/share access.
If you already have a Microsoft Graph access token (from another app / Postman / MSAL / etc.), three options:
# A) Env var (one-shot)
Persisting an access token and refresh token directly into ~/.onedrive-mcp/credentials.json creates a straightforward credential-theft target. Because refresh tokens can outlive access tokens, compromise may enable long-term reauthentication and continued data access even after the short-lived token expires.
export ONEDRIVE_ACCESS_TOKEN="eyJ0..."
./scripts/onedrive-files.sh list
# B) Helper (persists to ~/.onedrive-mcp/credentials.json)
./scripts/onedrive-token.sh set "eyJ0..." "refresh-token"
# C) Drop the JSON file directly
The documentation encourages manually writing raw bearer and refresh tokens into a JSON file, which increases the chance of leakage through shell history, editor backups, copied snippets, or mishandled files. In this skill's context, those tokens grant direct API access to cloud-stored content and sharing functions.
# C) Drop the JSON file directly
mkdir -p ~/.onedrive-mcp && chmod 700 ~/.onedrive-mcp
cat > ~/.onedrive-mcp/credentials.json <<EOF
{"token_type":"Bearer","access_token":"eyJ0...","refresh_token":"..."}
EOF
chmod 600 ~/.onedrive-mcp/credentials.json
Although chmod 600 hardens the file, the underlying issue remains that highly sensitive OAuth material is being stored locally in plaintext. Local storage is especially risky in multi-user systems, developer workstations, backups, and environments where logs or home directories may be collected.
cat > ~/.onedrive-mcp/credentials.json <<EOF {"token_type":"Bearer","access_token":"eyJ0...","refresh_token":"..."} EOF chmod 600 ~/.onedrive-mcp/credentials.json
## Notes
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.
- **Item IDs**: stable per drive. The `id` field is the full Graph ID — pass it as-is.
- **Path addressing**: use `/` separators (`Documents/Reports/q4.xlsx`). Scripts handle URL-encoding.
- **Conflict behavior**: uploads default to `replace`. Use the API directly for `rename` / `fail`.
- **Large uploads**: files > 4 MiB automatically use a resumable upload session (10 MiB chunks).
- **Download URLs**: `@microsoft.graph.downloadUrl` returned by the API is pre-authenticated and short-lived (minutes).
- **Deletes** move to the recycle bin (recoverable via the web UI for 30 days personal / 93 days business).
- **Throttling**: respect the `Retry-After` header on `429`.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
DELETE /me/drive/items/{item-id}
→ 204 No Content
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
DELETE /me/drive/items/{id}/permissions/{perm-id}
→ 204
The command writes the token exchange response directly to ~/.onedrive-mcp/credentials.json, which includes access and refresh tokens. Persisting reusable tokens in plaintext on disk creates a credential-theft target for local compromise, malware, shell-history mistakes, backup leakage, or accidental inclusion in sync/archive workflows.
--data-urlencode "redirect_uri=http://localhost"
--data-urlencode "grant_type=authorization_code"
--data-urlencode "scope=$SCOPES"
| tee ~/.onedrive-mcp/credentials.json | jq
chmod 600 ~/.onedrive-mcp/credentials.json
This line confirms continued reliance on a local credentials file containing sensitive OAuth material. While chmod 600 is protective, it does not eliminate risk from local account compromise or malware, especially because refresh tokens can extend access beyond the access token lifetime.
--data-urlencode "scope=$SCOPES"
| tee ~/.onedrive-mcp/credentials.json | jq
chmod 600 ~/.onedrive-mcp/credentials.json
You should see a JSON response with `access_token`, `refresh_token`, `expires_in`, etc.
The verification step reads the access token from the persisted credentials file, reinforcing operational dependence on locally stored bearer tokens. Bearer tokens are sufficient for API access if stolen, so documentation that normalizes reading them from plaintext files increases exposure risk.
TOKEN=$(jq -r '.access_token' ~/.onedrive-mcp/credentials.json)
curl -s "https://graph.microsoft.com/v1.0/me/drive" \
-H "Authorization: Bearer $TOKEN" \
| jq '{owner: .owner.user.displayName, total: .quota.total, used: .quota.used}'
The refresh flow depends on a refresh_token stored in credentials.json, which is more sensitive than a short-lived access token because it can mint new access tokens repeatedly. In the context of a OneDrive/SharePoint skill with broad delegated scopes, theft of this file can provide durable access to user or tenant data.
Access tokens expire after ~60 minutes. As long as refresh_token is present in credentials.json, refresh with:
./scripts/onedrive-token.sh refresh
The refresh flow depends on a refresh_token stored in credentials.json, which is more sensitive than a short-lived access token because it can mint new access tokens repeatedly. In the context of a OneDrive/SharePoint skill with broad delegated scopes, theft of this file can provide durable access to user or tenant data.
Access tokens expire after ~60 minutes. As long as refresh_token is present in credentials.json, refresh with:
./scripts/onedrive-token.sh refresh
This step reads the refresh token from a local plaintext file for token renewal, creating a reusable secret exposure point. Any attacker who obtains the file may silently maintain long-term access to Microsoft Graph resources covered by the granted scopes.
Or directly:
RT=$(jq -r '.refresh_token' ~/.onedrive-mcp/credentials.json)
curl -s -X POST "https://login.microsoftonline.com/common/oauth2/v2.0/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
--data-urlencode "client_id=$CLIENT_ID" \
Overwriting credentials.json with refreshed tokens continues plaintext persistence of newly rotated refresh tokens. Rotation helps invalidate old tokens, but the latest valid token remains exposed locally, so compromise of the file still yields durable account access.
--data-urlencode "refresh_token=$RT"
--data-urlencode "grant_type=refresh_token"
--data-urlencode "scope=$SCOPES" \
~/.onedrive-mcp/credentials.json
A new `refresh_token` is rotated on each call — always overwrite the file.
The BYO-token section encourages use of externally obtained Microsoft Graph access tokens with the skill, which can normalize handling bearer tokens across ad hoc sources without caution about provenance, scope, or storage. In a cloud-storage skill, accepting arbitrary high-privilege tokens increases the chance of accidental misuse or leakage.
A new `refresh_token` is rotated on each call — always overwrite the file.
## Using an existing access token (BYO token)
If you already have a Microsoft Graph access token from somewhere else (Postman, MSAL, another app, service principal, etc.):
Exporting an access token into an environment variable is convenient but can expose the token to shell history mistakes, process inspection in some environments, debugging output, or inherited subprocess contexts. Because this skill targets OneDrive and SharePoint data, a leaked bearer token may immediately grant file access within its scopes.
If you already have a Microsoft Graph access token from somewhere else (Postman, MSAL, another app, service principal, etc.):
# Option 1 — env var (one-off)
The script is explicitly designed to create a credentials file containing access and refresh tokens, which are powerful bearer secrets for Microsoft Graph and OneDrive. In the context of a cloud storage skill with broad default scopes such as 'Files.ReadWrite.All' and 'Sites.ReadWrite.All', compromise of these credentials can enable extensive data access and modification.
#
# Drops:
# ~/.onedrive-mcp/config.json client_id, client_secret
# ~/.onedrive-mcp/credentials.json access_token, refresh_token, expires_in
# Then refreshes the token at Microsoft Entra and probes Microsoft Graph
# (`/me/drive`) to confirm the install.
This line begins writing a plaintext credentials file containing bearer tokens to disk, creating a persistent target for credential theft. Because refresh tokens can often mint new access tokens, theft may provide durable unauthorized access to OneDrive and SharePoint data.
EOF
chmod 600 "$HOME/.onedrive-mcp/config.json"
cat > "$HOME/.onedrive-mcp/credentials.json" <<EOF
{
"token_type": "Bearer",
"access_token": "$ACCESS_TOKEN",
Although the file is permissioned 600, the script still persists high-value OAuth credentials under a root-owned path, making them available to any actor who later gains root access or accesses backups/snapshots. The risk is amplified by the broad Graph scopes configured by default, which may permit read/write access across files and sites.
"expires_in": 3600
}
EOF
chmod 600 "$HOME/.onedrive-mcp/credentials.json"
CREDS="$HOME/.onedrive-mcp/credentials.json"
RT_KEEP="$(jq -r '.refresh_token // empty' "$CREDS" | tr -d '\r\n\t ')"
No suspicious patterns detected.