Back to skill

Security audit

google-sheets

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Google Sheets integration, but it can delete sheet data and grant broad or public access without a clear confirmation policy.

Review before installing if the agent will have access to sensitive spreadsheets. Require explicit user approval before public/domain sharing, owner-role sharing, deleting rows or tabs, or exporting full spreadsheets to File Manager, and prefer pinned installer commands for related setup skills.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The schema includes a share action that can grant access to users, groups, domains, or 'anyone', including writer or owner-like roles, but this permission-management capability is not disclosed in the manifest description. Hidden sharing functionality is high risk because an agent or user may invoke it without appreciating that it can make sensitive spreadsheets accessible to external parties or publicly reachable.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The sharing documentation lacks a strong warning that the action can expose spreadsheets to external users, whole domains, or the public via the 'anyone' permission type. In a collaboration tool handling potentially sensitive business data, omission of this warning materially increases the chance of accidental oversharing and irreversible data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill exposes destructive and permission-changing capabilities such as delete_rows, delete_sheet, and share, but it does not present a clear, centralized warning or confirmation policy covering irreversible changes and access grants. In an agent-driven workflow, that omission can lead to accidental data loss or unintended sharing if the model invokes these actions without heightened safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'Search and activation keywords' list includes broad phrases such as 'google sheets', 'create reporting spreadsheets', and 'spreadsheet id', which could match many ordinary requests beyond this skill's intended scope. The file does not provide negative examples or tighter constraints for when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill instructs users to run npx skills ... without pinning an exact package version or commit, which creates a supply-chain risk: future package changes or a compromised upstream release could execute unexpected code during installation. Because this is an installation path for a skill ecosystem, users may trust and run it directly, increasing the chance of silent compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This line repeats an unpinned npx skills installation command, exposing users to execution of whatever version is current at install time. If the package or dependency chain is compromised, the installation step can become an initial access vector.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

An unversioned npx skills command appears again here, preserving the same supply-chain exposure. Users following documentation often treat install snippets as trusted, so a malicious or broken upstream update could affect all future installs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This installation example uses npx without a fixed version, allowing uncontrolled changes in fetched code over time. In a security-sensitive agent environment, such ambiguity weakens provenance and reproducibility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This repeated unpinned installer command carries the same remote code and dependency substitution risk as the other occurrences. Repetition across the skill increases the chance that operators will copy-paste a vulnerable install path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill again references npx skills without version pinning, which is a genuine supply-chain weakness rather than a purely stylistic issue. Installation instructions are part of the trust boundary because they can trigger code execution before the skill is even used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This final occurrence repeats the same unsafe installation pattern: floating npx execution from an external package source. The context does not mitigate the risk because the command is presented as normal setup guidance for users and agents.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 621)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-sheets-api
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 622)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-sheets-api
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The schema exposes an export capability that copies spreadsheet data into a separate File Manager system and supports multiple downloadable formats, which extends beyond the manifest's stated narrow 'Google Sheets' data-manipulation scope. This mismatch can mislead downstream agents or reviewers about where data can flow, increasing the risk of unintended exfiltration or policy bypass when sensitive sheet contents are exported.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The export documentation does not clearly warn that export-sheet copies spreadsheet contents into File Manager, creating an additional storage location with its own retention window and access considerations. Without an explicit warning, users and agents may treat export as a simple view/download operation rather than a data-duplication event, leading to accidental disclosure of sensitive data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.