Google Docs Create Document

Security checks across malware telemetry and agentic risk

Overview

This is a narrow Google Docs helper that creates a document through the local gog CLI, with no hidden installer or persistence found.

Install this only if you trust the local gog CLI and are comfortable with an agent using its configured Google account to create documents. Confirm the title and intended account before use, especially in automated workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to create a new Google Doc in an external user-owned service without any explicit warning, confirmation requirement, or scope limitation. That makes unintended data modification more likely, especially in autonomous or loosely supervised runs, because the action has side effects outside the local environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal