Google Drive Upload File

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple Google Drive upload helper, but users should only use it for files they intentionally want sent to Drive.

Install only if you are comfortable letting the agent invoke your configured `gog` CLI to upload chosen files to Google Drive. Before use, confirm the exact file path and Google account, and avoid uploading secrets, private keys, `.env` files, credentials, or other sensitive local data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs an agent to upload a local file to Google Drive but does not warn that this action transfers local data to an external cloud service. In agentic contexts, missing disclosure around outbound data movement can lead to unintended exfiltration of sensitive files, especially if the path is derived from prior steps or user-provided context without explicit confirmation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal