Back to skill

Security audit

Onedrive

Security checks for vulnerabilities and agentic risk

Overview

This skill provides real OneDrive management features, but it also uses broad Microsoft Graph access and includes under-disclosed host and token-handling risks.

Review before installing. Use this only if you need broad OneDrive and SharePoint write, delete, and sharing automation. Prefer reduced Microsoft Graph scopes, a dedicated account, and secure token storage. Avoid the bootstrap script on shared or production hosts, do not set ONEDRIVE_GRAPH_BASE with real tokens, and do not print or pass live access or refresh tokens in logged shells.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/onedrive-setup.sh:28
Finding

Privileged Execution of an Unpinned Remote Installation Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/onedrive-files.sh:11
Finding

Bearer Token Exfiltration Through an Unvalidated Graph API Base URL

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/onedrive-bootstrap.sh:46
Finding

Bootstrap Performs Unnecessary Host-Wide Process, Permission, and Shell-Profile Changes

Content
View full analysis
/dev/null || true ``` ```bash chmod 711 /root echo "[onedrive/setup] updating ~/.bashrc env exports..." sed -i '/ONEDRIVE_MCP/d' ~/.bashrc 2>/dev/null || true cat <<'EOF' >> ~/.bashrc export ONEDRIVE_MCP_CONFIG_DIR="/root/.onedrive-mcp" EOF ``` ### Technical Analysis Provisioning OAuth credentials and testing Microsoft Graph access does not require terminating all processes named `openclaw`, changing permissions on `/root`, or modifying the root user's shell initialization file. `killall openclaw` creates host-wide service disruption and may terminate unrelated or concurrent agent workloads. `chmod 711 /root` makes the root directory traversable by other local users, weakening the host's normal access-control boundary. Editing `~/.bashrc` creates a cross-session environment modification and hard-codes `/root/.onedrive-mcp`, even if the script is invoked in a different deployment context. These operations exceed the minimum privileges required for the declared OneDrive functionality and are not necessary for creating the protected credential directory or calling Microsoft APIs. ### Attack Path 1. An administrator or privileged deployment system runs the bootstrap script. 2. Every process named `openclaw` is terminated, interrupting active work. 3. `/root` is changed to mode `711`, allowing local users to traverse it when they know subordinate paths. 4. Root's `.bashrc` is modified. 5. Every future interactive root shell inherits the persistent OneDrive configuration path. 6. Other local weaknesses or known filenames may be combined with the relaxed root-directory traversal permission to access metadata or incorrectly permissioned descendant ...[truncated 384 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/onedrive-bootstrap.sh:120
Finding

Predictable Temporary Files Enable Symlink Overwrite Attacks and Metadata Leakage

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/onedrive-token.sh:107
Finding

OAuth Access and Refresh Tokens Are Passed Through Command-Line Arguments

Content
View full analysis
[refresh_token] local at="${1:-}" rt="${2:-}" if [ -z "$at" ]; then echo "Usage: onedrive-token.sh set [refresh_token]" >&2 exit 1 fi mkdir -p "$CONFIG_DIR" && chmod 700 "$CONFIG_DIR" local now=$(date +%s) jq -n --arg at "$at" --arg rt "$rt" --argjson now "$now" \ '{access_token:$at, refresh_token:(if $rt=="" then null else $rt end), token_type:"Bearer", expires_in:3600, acquired_at:$now, expires_at:($now+3600)}' \ > "$CREDS_FILE" chmod 600 "$CREDS_FILE" echo "{\"status\":\"saved\",\"file\":\"$CREDS_FILE\"}" } ``` ### Technical Analysis The documented and implemented `set` command accepts access and refresh tokens as positional command-line arguments. Such arguments can be stored in interactive shell history, terminal logs, audit logs, process-accounting records, or automation logs. On some platforms, other local users can also inspect process arguments while the command is running. The eventual use of mode `600` for `credentials.json` protects the resulting file but does not remove copies already exposed through argv or shell history. Refresh tokens are especially sensitive because they may enable access after the short-lived access token expires. ### Attack Path 1. A user follows the documented command and supplies live tokens on the comm ...[truncated 817 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/onedrive-setup.sh:14
Finding

Unconditional Default OAuth Scopes Exceed Least-Privilege Requirements

Content
View full analysis
/dev/null || true) sites_rw_all=$(az ad sp show --id "$GRAPH" --query "oauth2PermissionScopes[?value=='Sites.ReadWrite.All'].id" -o tsv 2>/dev/null || true) user_read=$(az ad sp show --id "$GRAPH" --query "oauth2PermissionScopes[?value=='User.Read'].id" -o tsv 2>/dev/null || true) local perms=() [ -n "$files_rw_all" ] && perms+=("$files_rw_all=Scope") [ -n "$sites_rw_all" ] && perms+=("$sites_rw_all=Scope") [ -n "$user_read" ] && perms+=("$user_read=Scope") if [ ${#perms[@]} -gt 0 ]; then az ad app permission add --id "$APP_ID" --api "$GRAPH" \ --api-permissions "${perms[@]}" 2>/dev/null || true fi echo -e "${GREEN}✓ Permissions: Files.ReadWrite.All, Sites.ReadWrite.All, User.Read${NC}" echo -e " (offline_access is requested at sign-in, not declared here)" } ``` From `scripts/onedrive-bootstrap.sh`: ```bash [ "$SCOPE" = "__ONEDRIVE_SCOPES__" ] && SCOPE="https://graph.microsoft.com/Files.ReadWrite.All https://graph.microsoft.com/Sites.ReadWrite.All https://graph.microsoft.com/User.Read offline_access" ``` From `references/permissions.md`: ```text This skill requests `Files.ReadWrite.A ...[truncated 1922 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (86)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill presents itself as file management but also includes raw access-token display, local credential persistence, and user-profile retrieval via /me. These are materially different from ordinary file operations and increase the chance of credential misuse or unintended data exposure under the guise of a benign storage skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill presents itself as file management but also includes raw access-token display, local credential persistence, and user-profile retrieval via /me. These are materially different from ordinary file operations and increase the chance of credential misuse or unintended data exposure under the guise of a benign storage skill.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

A command that prints the raw access token to stdout creates immediate leakage risk via terminal scrollback, shell history capture, logging wrappers, CI output, or clipboard mishandling. Since bearer tokens are usable as-is, anyone who obtains the printed value can act as the user until expiry, and potentially longer if combined with refresh-token workflows.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

bash
./scripts/onedrive-token.sh refresh  # Refresh expired token
./scripts/onedrive-token.sh test     # Test connection
./scripts/onedrive-token.sh get      # Print access token
./scripts/onedrive-token.sh info     # Show token info / expiry
./scripts/onedrive-token.sh me       # Show signed-in user

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

Token Refresh

Access tokens expire after ~1 hour. Refresh with:

bash
./scripts/onedrive-token.sh refresh

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly stores OAuth tokens and client secrets in local files, which are highly sensitive credentials. If those files are exposed through backups, misconfigured permissions, malware, or accidental disclosure, an attacker could gain persistent access to OneDrive and SharePoint data under broad delegated scopes.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
## Files

- `~/.onedrive-mcp/config.json` — Client ID, secret, tenant, scopes
- `~/.onedrive-mcp/credentials.json` — OAuth tokens (access + refresh)

Both files are `chmod 600`, directory `700`. Never commit them.

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

The 'Bring Your Own Access Token' section encourages use of externally obtained Graph tokens inside the skill. That is not inherently malicious, but in this context it normalizes handling raw bearer tokens and increases the likelihood of unsafe copy/paste, reuse of overprivileged tokens, and accidental disclosure.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
Discover drive IDs with `./scripts/onedrive-files.sh drives`.

## Bring Your Own Access Token

If you already have a Microsoft Graph access token (from another app / Postman / MSAL / etc.), three options:

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Documenting environment-variable injection of access tokens can expose credentials through process listings, shell history, crash dumps, debug tooling, or inherited environments. In a cloud-file-management skill with broad scopes, that can translate directly into unauthorized read/write/share access.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

Bring Your Own Access Token

If you already have a Microsoft Graph access token (from another app / Postman / MSAL / etc.), three options:

bash
# A) Env var (one-shot)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Persisting an access token and refresh token directly into ~/.onedrive-mcp/credentials.json creates a straightforward credential-theft target. Because refresh tokens can outlive access tokens, compromise may enable long-term reauthentication and continued data access even after the short-lived token expires.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

md
export ONEDRIVE_ACCESS_TOKEN="eyJ0..."
./scripts/onedrive-files.sh list

# B) Helper (persists to ~/.onedrive-mcp/credentials.json)
./scripts/onedrive-token.sh set "eyJ0..." "refresh-token"

# C) Drop the JSON file directly

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The documentation encourages manually writing raw bearer and refresh tokens into a JSON file, which increases the chance of leakage through shell history, editor backups, copied snippets, or mishandled files. In this skill's context, those tokens grant direct API access to cloud-stored content and sharing functions.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
# C) Drop the JSON file directly
mkdir -p ~/.onedrive-mcp && chmod 700 ~/.onedrive-mcp
cat > ~/.onedrive-mcp/credentials.json <<EOF
{"token_type":"Bearer","access_token":"eyJ0...","refresh_token":"..."}
EOF
chmod 600 ~/.onedrive-mcp/credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Although chmod 600 hardens the file, the underlying issue remains that highly sensitive OAuth material is being stored locally in plaintext. Local storage is especially risky in multi-user systems, developer workstations, backups, and environments where logs or home directories may be collected.

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

cat > ~/.onedrive-mcp/credentials.json <<EOF {"token_type":"Bearer","access_token":"eyJ0...","refresh_token":"..."} EOF chmod 600 ~/.onedrive-mcp/credentials.json

text

## Notes

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
- **Item IDs**: stable per drive. The `id` field is the full Graph ID — pass it as-is.
- **Path addressing**: use `/` separators (`Documents/Reports/q4.xlsx`). Scripts handle URL-encoding.
- **Conflict behavior**: uploads default to `replace`. Use the API directly for `rename` / `fail`.
- **Large uploads**: files > 4 MiB automatically use a resumable upload session (10 MiB chunks).
- **Download URLs**: `@microsoft.graph.downloadUrl` returned by the API is pre-authenticated and short-lived (minutes).
- **Deletes** move to the recycle bin (recoverable via the web UI for 30 days personal / 93 days business).
- **Throttling**: respect the `Retry-After` header on `429`.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 162)May include surrounding context.

Delete

text
DELETE /me/drive/items/{item-id}
→ 204 No Content

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-reference.md (reported line 383)May include surrounding context.

Revoke a permission

text
DELETE /me/drive/items/{id}/permissions/{perm-id}
→ 204

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The command writes the token exchange response directly to ~/.onedrive-mcp/credentials.json, which includes access and refresh tokens. Persisting reusable tokens in plaintext on disk creates a credential-theft target for local compromise, malware, shell-history mistakes, backup leakage, or accidental inclusion in sync/archive workflows.

Content

Scanner excerpt · references/setup.md (reported line 106)May include surrounding context.

--data-urlencode "redirect_uri=http://localhost"
--data-urlencode "grant_type=authorization_code"
--data-urlencode "scope=$SCOPES"
| tee ~/.onedrive-mcp/credentials.json | jq

chmod 600 ~/.onedrive-mcp/credentials.json

text

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

This line confirms continued reliance on a local credentials file containing sensitive OAuth material. While chmod 600 is protective, it does not eliminate risk from local account compromise or malware, especially because refresh tokens can extend access beyond the access token lifetime.

Content

Scanner excerpt · references/setup.md (reported line 108)May include surrounding context.

--data-urlencode "scope=$SCOPES"
| tee ~/.onedrive-mcp/credentials.json | jq

chmod 600 ~/.onedrive-mcp/credentials.json

text

You should see a JSON response with `access_token`, `refresh_token`, `expires_in`, etc.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The verification step reads the access token from the persisted credentials file, reinforcing operational dependence on locally stored bearer tokens. Bearer tokens are sufficient for API access if stolen, so documentation that normalizes reading them from plaintext files increases exposure risk.

Content

Scanner excerpt · references/setup.md (reported line 116)May include surrounding context.

Step 7 — Verify

bash
TOKEN=$(jq -r '.access_token' ~/.onedrive-mcp/credentials.json)
curl -s "https://graph.microsoft.com/v1.0/me/drive" \
  -H "Authorization: Bearer $TOKEN" \
  | jq '{owner: .owner.user.displayName, total: .quota.total, used: .quota.used}'

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The refresh flow depends on a refresh_token stored in credentials.json, which is more sensitive than a short-lived access token because it can mint new access tokens repeatedly. In the context of a OneDrive/SharePoint skill with broad delegated scopes, theft of this file can provide durable access to user or tenant data.

Content

Scanner excerpt · references/setup.md (reported line 132)May include surrounding context.

Refreshing tokens

Access tokens expire after ~60 minutes. As long as refresh_token is present in credentials.json, refresh with:

bash
./scripts/onedrive-token.sh refresh

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The refresh flow depends on a refresh_token stored in credentials.json, which is more sensitive than a short-lived access token because it can mint new access tokens repeatedly. In the context of a OneDrive/SharePoint skill with broad delegated scopes, theft of this file can provide durable access to user or tenant data.

Content

Scanner excerpt · references/setup.md (reported line 132)May include surrounding context.

Refreshing tokens

Access tokens expire after ~60 minutes. As long as refresh_token is present in credentials.json, refresh with:

bash
./scripts/onedrive-token.sh refresh

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This step reads the refresh token from a local plaintext file for token renewal, creating a reusable secret exposure point. Any attacker who obtains the file may silently maintain long-term access to Microsoft Graph resources covered by the granted scopes.

Content

Scanner excerpt · references/setup.md (reported line 141)May include surrounding context.

Or directly:

bash
RT=$(jq -r '.refresh_token' ~/.onedrive-mcp/credentials.json)
curl -s -X POST "https://login.microsoftonline.com/common/oauth2/v2.0/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  --data-urlencode "client_id=$CLIENT_ID" \

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

Overwriting credentials.json with refreshed tokens continues plaintext persistence of newly rotated refresh tokens. Rotation helps invalidate old tokens, but the latest valid token remains exposed locally, so compromise of the file still yields durable account access.

Content

Scanner excerpt · references/setup.md (reported line 149)May include surrounding context.

--data-urlencode "refresh_token=$RT"
--data-urlencode "grant_type=refresh_token"
--data-urlencode "scope=$SCOPES" \

~/.onedrive-mcp/credentials.json

text

A new `refresh_token` is rotated on each call — always overwrite the file.

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The BYO-token section encourages use of externally obtained Microsoft Graph access tokens with the skill, which can normalize handling bearer tokens across ad hoc sources without caution about provenance, scope, or storage. In a cloud-storage skill, accepting arbitrary high-privilege tokens increases the chance of accidental misuse or leakage.

Content

Scanner excerpt · references/setup.md (reported line 154)May include surrounding context.

md
A new `refresh_token` is rotated on each call — always overwrite the file.

## Using an existing access token (BYO token)

If you already have a Microsoft Graph access token from somewhere else (Postman, MSAL, another app, service principal, etc.):

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Exporting an access token into an environment variable is convenient but can expose the token to shell history mistakes, process inspection in some environments, debugging output, or inherited subprocess contexts. Because this skill targets OneDrive and SharePoint data, a leaked bearer token may immediately grant file access within its scopes.

Content

Scanner excerpt · references/setup.md (reported line 156)May include surrounding context.

Using an existing access token (BYO token)

If you already have a Microsoft Graph access token from somewhere else (Postman, MSAL, another app, service principal, etc.):

bash
# Option 1 — env var (one-off)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The script is explicitly designed to create a credentials file containing access and refresh tokens, which are powerful bearer secrets for Microsoft Graph and OneDrive. In the context of a cloud storage skill with broad default scopes such as 'Files.ReadWrite.All' and 'Sites.ReadWrite.All', compromise of these credentials can enable extensive data access and modification.

Content

Scanner excerpt · scripts/onedrive-bootstrap.sh (reported line 9)May include surrounding context.

sh
#
# Drops:
#   ~/.onedrive-mcp/config.json       client_id, client_secret
#   ~/.onedrive-mcp/credentials.json  access_token, refresh_token, expires_in
# Then refreshes the token at Microsoft Entra and probes Microsoft Graph
# (`/me/drive`) to confirm the install.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line begins writing a plaintext credentials file containing bearer tokens to disk, creating a persistent target for credential theft. Because refresh tokens can often mint new access tokens, theft may provide durable unauthorized access to OneDrive and SharePoint data.

Content

Scanner excerpt · scripts/onedrive-bootstrap.sh (reported line 63)May include surrounding context.

sh
EOF
chmod 600 "$HOME/.onedrive-mcp/config.json"

cat > "$HOME/.onedrive-mcp/credentials.json" <<EOF
{
  "token_type": "Bearer",
  "access_token": "$ACCESS_TOKEN",

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

Although the file is permissioned 600, the script still persists high-value OAuth credentials under a root-owned path, making them available to any actor who later gains root access or accesses backups/snapshots. The risk is amplified by the broad Graph scopes configured by default, which may permit read/write access across files and sites.

Content

Scanner excerpt · scripts/onedrive-bootstrap.sh (reported line 71)May include surrounding context.

sh
"expires_in": 3600
}
EOF
chmod 600 "$HOME/.onedrive-mcp/credentials.json"

CREDS="$HOME/.onedrive-mcp/credentials.json"
RT_KEEP="$(jq -r '.refresh_token // empty' "$CREDS" | tr -d '\r\n\t ')"

Static analysis

No suspicious patterns detected.