Back to skill

Security audit

Google Service Accounts

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Google service-account helper, but it handles powerful Google credentials and includes examples that can write to live Docs and Sheets.

Install only if you are comfortable giving an agent access to Google resources through a service account. Keep credentials.json out of shared folders and source control, share only the specific files or calendars needed, prefer read-only scopes when possible, and run the write examples first on test documents.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
quickstart.py:17
Finding

Write Examples Mutate Live Google Resources Without Meaningful Target Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 218)May include surrounding context.

python
from google_auth_oauthlib.flow import InstalledAppFlow
flow = InstalledAppFlow.from_client_secrets_file(
    "client_secret.json", scopes=["https://www.googleapis.com/auth/calendar.readonly"])
creds = flow.run_local_server(port=0)   # opens a browser the FIRST time, then save creds.to_json()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 347)May include surrounding context.

md
## Sources

- gspread — Authentication: <https://docs.gspread.org/en/latest/oauth2.html>
- Google Workspace — Create access credentials: <https://developers.google.com/workspace/guides/create-credentials>
- Service accounts overview (IAM): <https://cloud.google.com/iam/docs/service-account-overview>
- Using OAuth 2.0 for server-to-server applications (service accounts): <https://developers.google.com/identity/protocols/oauth2/service-account>
- OAuth 2.0 scopes for Google APIs: <https://developers.google.com/identity/protocols/oauth2/scopes>

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 75)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 119)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 156)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 250)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 310)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 323)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · quickstart.py (reported line 4)May include surrounding context.

python
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · quickstart.py (reported line 14)May include surrounding context.

python
---
name: google-service-accounts
description: Read or write a user's Google Sheets, Docs, Drive, or Calendar from code via a Google service account — headless, no OAuth browser flow. Use when handed a credentials.json or CREDS_JSON, or when the user wants to set one up (including walking them through the free signup, which needs only a basic Google account).
---

# Google service accounts

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The setup flow explicitly generates a long-lived private key file on disk as credentials.json. Even though this is standard Google service-account behavior, having the skill create and rely on a reusable key materially increases secret-exposure risk if the workspace is shared, persisted, or later accessed by other tools or agents.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

docs.googleapis.com calendar-json.googleapis.com gcloud iam service-accounts create agent-bot --display-name="Agent Bot" SA="agent-bot@${PROJECT}.iam.gserviceaccount.com" gcloud iam service-accounts keys create credentials.json --iam-account="$SA" echo "Now share your file/calendar with: $SA"

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
OAuth — the "Sign in with Google → allow access?" flow — exists to let an app borrow **a human's**
identity, so a human has to be there to click "Allow." An autonomous agent isn't. A service account
is its *own* identity: headless, no consent screen, no token expiry to babysit — exactly what you
want for a bot that runs at 3am.

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs use of external Google APIs and includes code that performs network-backed operations, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, that mismatch can bypass governance and make it harder to constrain or audit outbound actions involving user documents and calendars.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Sheets example performs an immediate live write to the first worksheet after opening the spreadsheet, with no dry-run mode, confirmation prompt, or explicit warning at the mutation point. In an agent or automation context, this can cause unintended modification of user data, especially if the spreadsheet name resolves to a production document shared with the service account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code reads a service-account key from credentials.json, which is a sensitive credential source. While the module docstring mentions the prerequisite file, it does not clearly warn that the script will access credential material, and there is no inline user-facing disclosure at the point of use.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency 'gspread' is unpinned, so installs will resolve to whatever version is current at install time. This weakens build reproducibility and can expose the skill to breaking changes or a compromised/upstream-vulnerable release via the software supply chain. In this skill, which handles Google service account access to Sheets/Docs/Drive/Calendar, dependency integrity matters because the libraries may process sensitive credentials and API data.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
gspread
google-api-python-client
google-auth
google-auth-oauthlib

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency 'google-api-python-client' is unpinned, allowing different versions to be installed over time without review. This creates supply-chain and reliability risk, including accidental adoption of vulnerable or incompatible releases; because this package interfaces directly with Google APIs, an unsafe version could affect access to user data or service-account operations.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
gspread
google-api-python-client
google-auth
google-auth-oauthlib

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency 'google-auth' is unpinned, so environment rebuilds may pull in arbitrary newer releases. Since this library is involved in authentication flows and credential handling, using unreviewed versions increases the risk of supply-chain compromise, auth regressions, or exposure to newly introduced vulnerabilities.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
gspread
google-api-python-client
google-auth
google-auth-oauthlib

Static analysis

No suspicious patterns detected.