T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Google service-account helper, but it handles powerful Google credentials and includes examples that can write to live Docs and Sheets.
Install only if you are comfortable giving an agent access to Google resources through a service account. Keep credentials.json out of shared folders and source control, share only the specific files or calendars needed, prefer read-only scopes when possible, and run the write examples first on test documents.
requirements.txt:1Unpinned Third-Party Dependencies Create a Supply-Chain Risk
quickstart.py:17Write Examples Mutate Live Google Resources Without Meaningful Target Validation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from google_auth_oauthlib.flow import InstalledAppFlow
flow = InstalledAppFlow.from_client_secrets_file(
"client_secret.json", scopes=["https://www.googleapis.com/auth/calendar.readonly"])
creds = flow.run_local_server(port=0) # opens a browser the FIRST time, then save creds.to_json()
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Sources
- gspread — Authentication: <https://docs.gspread.org/en/latest/oauth2.html>
- Google Workspace — Create access credentials: <https://developers.google.com/workspace/guides/create-credentials>
- Service accounts overview (IAM): <https://cloud.google.com/iam/docs/service-account-overview>
- Using OAuth 2.0 for server-to-server applications (service accounts): <https://developers.google.com/identity/protocols/oauth2/service-account>
- OAuth 2.0 scopes for Google APIs: <https://developers.google.com/identity/protocols/oauth2/scopes>
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---
# Google service accounts
The setup flow explicitly generates a long-lived private key file on disk as credentials.json. Even though this is standard Google service-account behavior, having the skill create and rely on a reusable key materially increases secret-exposure risk if the workspace is shared, persisted, or later accessed by other tools or agents.
docs.googleapis.com calendar-json.googleapis.com gcloud iam service-accounts create agent-bot --display-name="Agent Bot" SA="agent-bot@${PROJECT}.iam.gserviceaccount.com" gcloud iam service-accounts keys create credentials.json --iam-account="$SA" echo "Now share your file/calendar with: $SA"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
OAuth — the "Sign in with Google → allow access?" flow — exists to let an app borrow **a human's**
identity, so a human has to be there to click "Allow." An autonomous agent isn't. A service account
is its *own* identity: headless, no consent screen, no token expiry to babysit — exactly what you
want for a bot that runs at 3am.
---
The skill clearly instructs use of external Google APIs and includes code that performs network-backed operations, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, that mismatch can bypass governance and make it harder to constrain or audit outbound actions involving user documents and calendars.
The Sheets example performs an immediate live write to the first worksheet after opening the spreadsheet, with no dry-run mode, confirmation prompt, or explicit warning at the mutation point. In an agent or automation context, this can cause unintended modification of user data, especially if the spreadsheet name resolves to a production document shared with the service account.
This code reads a service-account key from credentials.json, which is a sensitive credential source. While the module docstring mentions the prerequisite file, it does not clearly warn that the script will access credential material, and there is no inline user-facing disclosure at the point of use.
The dependency 'gspread' is unpinned, so installs will resolve to whatever version is current at install time. This weakens build reproducibility and can expose the skill to breaking changes or a compromised/upstream-vulnerable release via the software supply chain. In this skill, which handles Google service account access to Sheets/Docs/Drive/Calendar, dependency integrity matters because the libraries may process sensitive credentials and API data.
gspread
google-api-python-client
google-auth
google-auth-oauthlib
The dependency 'google-api-python-client' is unpinned, allowing different versions to be installed over time without review. This creates supply-chain and reliability risk, including accidental adoption of vulnerable or incompatible releases; because this package interfaces directly with Google APIs, an unsafe version could affect access to user data or service-account operations.
gspread
google-api-python-client
google-auth
google-auth-oauthlib
The dependency 'google-auth' is unpinned, so environment rebuilds may pull in arbitrary newer releases. Since this library is involved in authentication flows and credential handling, using unreviewed versions increases the risk of supply-chain compromise, auth regressions, or exposure to newly introduced vulnerabilities.
gspread
google-api-python-client
google-auth
google-auth-oauthlib
No suspicious patterns detected.