Google Docs Update Document

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple Google Docs editing helper that matches its stated purpose, though users should verify the target document before allowing edits.

Install this only if you want Codex to modify Google Docs through your configured `gog` access. Before approving use, confirm the Google account, exact document ID or URL, and the text to write or replace, especially for shared or sensitive documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation condition is overly broad: any situation where text "needs to be added, written, or updated" could trigger a live modification to an existing Google Doc without explicit authorization, target validation, or content safety checks. In an agent setting, this increases the chance of unintended document edits, prompt-influenced tampering, or modification of the wrong document when upstream context is ambiguous or adversarial.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal