Back to skill

Security audit

gogcli-mcp-gmail

Security checks for vulnerabilities and agentic risk

Overview

This is a real Gmail connector, but it needs Review because some destructive Gmail and account-setting deletions can be forced without a separate user-confirmation flow.

Install only if you are comfortable granting broad Gmail read/write and settings authority. Prefer a dedicated account or enable GOG_READONLY when you only need reads, use a secure keyring backend with strong host isolation, and be especially cautious before allowing agents to delete labels, filters, drafts, or send-as aliases.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:3090
Finding

Label deletion bypasses code-enforced user confirmation

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:3090-3099
Vulnerability Type: Destructive operation without user confirmation
Risk Level: Medium

Vulnerable Code

ts
server.registerTool('gog_gmail_labels_delete', {
  description: 'Delete a Gmail label.',
  annotations: { destructiveHint: true },
  inputSchema: z.object({
    labelIdOrName: z.string().describe('Label ID or name to delete'),
    account: accountParam,
  }),
}, async ({ labelIdOrName, account }) => {
  return runOrDiagnose(['gmail', 'labels', 'delete', pos(labelIdOrName), '--force'], { account }); // gog gates this op; without --force the runner's --no-input makes it refuse
});

Technical Analysis

The handler unconditionally appends --force, explicitly bypassing gog's non-interactive safety refusal. The destructiveHint annotation informs the client that the operation is destructive but does not enforce approval.

The project already contains a host-mediated confirmation and confirmation-token mechanism for higher-risk actions such as sending mail and permanently deleting messages. This label-deletion path does not use that mechanism. Consequently, an MCP caller or agent decision is treated as equivalent to the Gmail account owner's explicit approval.

The attacker-controlled input is labelIdOrName, while the dangerous operation is the forced deletion performed using the server's authenticated Gmail account. The crossed trust boundary is between an agent-generated tool request and an account-owner-authorized destructive change.

Attack Path

  1. The Skill is connected to an authenticated Gmail account.
  2. An agent selects or is induced to select a label identifier, potentially while processing untrusted email content.
  3. The agent invokes gog_gmail_labels_delete.
  4. The handler automatically adds --force.
  5. gog deletes the label without a host confirmation prompt or confirmation token.

Impact Assessment

An attacker does not obtain ad ...[truncated 310 chars]

Remediation
View remediation

Remediation Suggestions

Use the existing requireDispatchConfirmation mechanism before adding --force.

The confirmation should:

  1. Fetch the current label metadata and counts.
  2. Display the exact account, label ID, label name, and affected message/thread counts.
  3. Bind the confirmation token to the account and exact label identifier.
  4. Re-read the label before deletion and invalidate approval if its identity or relevant metadata changed.
  5. Append --force only after successful host elicitation or validation of an unexpired, single-use confirmation token.
  6. Refuse the operation when confirmation cannot be displayed and the server is configured for refusal mode.

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:3605
Finding

Permanent draft deletion relies on a caller-controlled force flag instead of user confirmation

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:3605-3616
Vulnerability Type: Irreversible deletion without host-mediated confirmation
Risk Level: Medium

Vulnerable Code

ts
server.registerTool('gog_gmail_drafts_delete', {
  description: 'Permanently delete a Gmail draft (not reversible — drafts do not go to Trash). Requires force:true to delete non-interactively.',
  annotations: { destructiveHint: true },
  inputSchema: z.object({
    draftId: z.string().describe('Draft ID'),
    force: z.boolean().optional().describe('Required to delete in this non-interactive context — without it the delete is refused as a safety guard.'),
    account: accountParam,
  }),
}, async ({ draftId, account, force }) => {
  const args: GogArg[] = ['gmail', 'drafts', 'delete', pos(draftId)];
  if (force) args.push('--force');
  return runOrDiagnose(args, { account });
});

Technical Analysis

The force parameter is supplied by the MCP caller or agent. It proves only that the caller set a Boolean value; it does not prove that the account owner reviewed and approved the draft deletion.

When force: true is supplied, the handler appends --force, bypassing gog's non-interactive refusal. Unlike gog_gmail_drafts_send, the deletion path does not fetch the stored draft for preview, invoke host elicitation, or require a confirmation token bound to the draft's current contents.

The attacker-controlled points are draftId and force. The dangerous operation is permanent draft deletion. The trust boundary crossed is between an agent-controlled request and explicit authorization from the Gmail account owner.

Attack Path

  1. The Skill runs with access to an authenticated Gmail account.
  2. An agent obtains or selects a draft ID.
  3. The agent invokes gog_gmail_drafts_delete with force: true, whether through error, unsafe automation, or influence from untrusted content.
  4. The wrapper passes --force to gog.
  5. The draft is permanen ...[truncated 422 chars]
Remediation
View remediation

Remediation Suggestions

Replace the caller-controlled force gate with the existing two-phase confirmation framework:

  1. Fetch the draft before deletion.
  2. Show recipients, subject, a bounded body preview, and attachment names.
  3. Generate a single-use confirmation token bound to the account, draft ID, message ID, and a digest of the current draft.
  4. Re-fetch the draft during the confirmed call.
  5. Refuse deletion and issue a fresh preview if the draft changed.
  6. Add --force only after successful confirmation.
  7. Remove or deprecate the public force Boolean so an agent cannot self-authorize permanent deletion.

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:4137
Finding

Gmail filter deletion bypasses upstream safety controls

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:4137-4145
Vulnerability Type: Security-relevant configuration deletion without confirmation
Risk Level: Medium

Vulnerable Code

ts
server.registerTool('gog_gmail_filters_delete', {
  description: 'Delete a Gmail filter by ID.',
  annotations: { destructiveHint: true },
  inputSchema: z.object({
    filterId: z.string().describe('Filter ID to delete'),
    account: accountParam,
  }),
}, async ({ filterId, account }) => {
  return runOrDiagnose(['gmail', 'settings', 'filters', 'delete', pos(filterId), '--force'], { account }); // gog gates this op; without --force the runner's --no-input makes it refuse
});

Technical Analysis

The handler always adds --force, overriding gog's built-in non-interactive refusal. No code-enforced confirmation occurs, and the filter is not fetched and displayed before deletion.

Filters can implement security- and workflow-relevant behavior, including labeling, archiving, spam handling, forwarding, and trashing. Although creating a forwarding filter receives special confirmation elsewhere in this project, deleting any existing filter does not.

The attacker-controlled input is filterId. The dangerous operation is forced deletion of persistent Gmail configuration. The trust boundary crossed is between an agent-issued MCP call and the account owner's authorization to remove an ongoing mailbox rule.

Attack Path

  1. The Skill is authorized for a Gmail account.
  2. An agent identifies or is supplied with a filter ID.
  3. The agent invokes gog_gmail_filters_delete.
  4. The wrapper automatically adds --force.
  5. The selected persistent filter is removed without showing its criteria and actions to the user.

Impact Assessment

Deletion can disable mailbox organization, spam-handling rules, retention workflows, forwarding behavior, or other automated processing. This does not expand the attacker's OAuth privileges, but it permits unaut ...[truncated 83 chars]

Remediation
View remediation

Remediation Suggestions

Require host-mediated confirmation before filter deletion:

  1. Fetch the filter using gmail settings filters get.
  2. Show its complete criteria and actions, especially forwarding, trash, archive, and spam-related actions.
  3. Bind a single-use confirmation token to the account, filter ID, and a canonical digest of the fetched filter.
  4. Re-fetch and compare the filter during the confirmed call.
  5. Append --force only after confirmation succeeds.
  6. Log the confirmed deletion without logging credentials or unrelated message content.

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/gmail-extra.ts:4233
Finding

Send-as identity deletion is forced without explicit user approval

Content
View full analysis

Vulnerability Details

File Location: src/tools/gmail-extra.ts:4233-4241
Vulnerability Type: Account identity configuration deletion without confirmation
Risk Level: Medium

Vulnerable Code

ts
server.registerTool('gog_gmail_sendas_delete', {
  description: 'Delete a send-as alias by its email address.',
  annotations: { destructiveHint: true },
  inputSchema: z.object({
    email: z.string().describe('Send-as alias email address to delete'),
    account: accountParam,
  }),
}, async ({ email, account }) => {
  return runOrDiagnose(['gmail', 'settings', 'sendas', 'delete', pos(email), '--force'], { account }); // gog gates this op; without --force the runner's --no-input makes it refuse
});

Technical Analysis

The tool unconditionally supplies --force, bypassing gog's non-interactive safety gate. The destructive annotation is advisory and does not require the user to approve the deletion.

The project requires confirmation when creating a send-as identity, but the corresponding deletion path has no equivalent control. The input email address is selected by the MCP caller, and the operation executes using the server's authenticated Gmail privileges.

The attacker-controlled point is email. The dangerous operation is deletion of an account-level sending identity. The crossed trust boundary is between an agent-issued tool call and the account owner's explicit authorization to modify Gmail identity configuration.

Attack Path

  1. The Skill has authenticated access to a Gmail account with one or more send-as aliases.
  2. An agent selects an alias address, potentially due to unsafe automation or untrusted content influencing tool selection.
  3. The agent invokes gog_gmail_sendas_delete.
  4. The handler automatically supplies --force.
  5. Gmail removes the selected send-as identity without a user confirmation prompt.

Impact Assessment

The affected account can lose the ability to send mail from the selected alias until it is ...[truncated 258 chars]

Remediation
View remediation

Remediation Suggestions

Apply the same confirmation design used by gog_gmail_sendas_create:

  1. Fetch the alias and show its address, display name, reply-to address, verification state, and whether it is the default identity.
  2. Bind the confirmation token to the Gmail account and exact alias address.
  3. Re-fetch the alias during the confirmed call and reject stale approval if its state changed.
  4. Add --force only after successful user confirmation.
  5. Add additional protection or refuse deletion if the alias is the default sending identity, unless the user explicitly confirms that consequence.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (71)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should handle Gmail operations beyond simple search/send. However, the code shown contains no Gmail API calls, no authentication flow, no message/thread/label/draft/attachment handling, and no email operations at all. Instead, it is infrastructure code from a schema validation library, centered on parsing and validating JavaScript data structures and generating localized errors. This is a materially different primary purpose and an unrelated capability set, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should support advanced Gmail workflows and include auth/Gmail tools only. However, the provided code is unrelated to Gmail: it defines localized error message formatters for validation issues such as invalid type, invalid format, too big/small, and unrecognized keys across multiple languages. There is no evidence of Gmail API calls, mail reading/sending, thread management, label manipulation, forwarding, draft creation, attachment handling, bulk archive/trash operations, or authentication logic. This is a clear description-behavior mismatch with a materially different primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for in-depth Gmail operations, but the code shown only defines localized validation error messages for Zod (e.g., invalid_type, too_big, invalid_format) across multiple languages. There is no evidence of Gmail API access, message/thread/label handling, drafting, forwarding, attachments, auth flows, or any email-related logic. This is a clear description-behavior mismatch with a materially different primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says this skill should handle in-depth Gmail operations such as threads, labels, drafts, attachments, forwarding, and bulk mailbox actions. However, the provided code is clearly from the Zod validation library: it defines localized error messages, registry/compile helpers, schema/type checks, and parser generation logic. There is no evidence of Gmail API calls, authentication flows, message/thread handling, labels, drafts, attachments, or email actions. This is a material mismatch in primary purpose and capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for in-depth Gmail operations, but the code shown contains no Gmail API calls, no auth flows, no mailbox/thread/label/draft handling, and no email-specific actions. Instead, it implements generic Zod schema functionality: creating types like string/number/object/union, applying checks like min/max/regex, processing schemas into JSON Schema, and parse/encode/decode behavior. This is a materially different primary purpose and an unrelated capability set, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear mismatch. The declared description says the skill is for advanced Gmail actions, but the supplied code contains no Gmail-specific behavior such as reading messages, managing threads/labels, sending drafts, forwarding, attachments, or bulk mailbox operations. Instead, it is infrastructure code for schema conversion/validation and Model Context Protocol/OAuth definitions. That is a materially different primary purpose from the declared Gmail functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should be used for in-depth Gmail operations. However, the supplied code does not show any Gmail integration, Gmail API calls, message/thread/label handling, drafting/sending/forwarding logic, or mailbox-specific tooling. Instead, it defines broad protocol schemas and runtime behavior for a generic MCP/JSON-RPC system, including request validation, notifications, result handling, caching, subscriptions, and error types. That is a materially different primary purpose from a Gmail operations skill, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is specifically for advanced Gmail work. However, the supplied code is not Gmail-related: it contains generic protocol/SDK internals such as transport sending, JSON-RPC notification handling, request/notification registration, schema validation, buffering, content-type parsing, and validator/codegen utilities. There is no evidence of Gmail resources, Gmail API calls, mailbox/thread/label/draft/attachment operations, or auth flows tied to Gmail. This is a clear description-behavior mismatch because the actual code’s primary purpose is infrastructure/library support rather than Gmail functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a production Gmail operations skill intended to help users work with Gmail in depth. The supplied code chunk does not implement Gmail user-facing actions like reading, organizing, forwarding, or bulk mailbox operations. Instead, it is a test file that exercises and validates one internal Gmail-related tool (gog_gmail_drafts_diff) using mocks and assertions. While Gmail draft diffing is loosely related to Gmail tooling, the primary behavior here is software testing of internal arithmetic correctness, which is materially different from the declared operational purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk does not implement or invoke Gmail operations such as reading threads, managing labels, forwarding, drafting via Gmail APIs, handling attachments, or bulk mailbox actions. Instead, it contains unit tests for helper functions that strip signatures and compare authored prose between draft bodies. While the logic is email-related, its primary behavior is internal test coverage for body-agreement heuristics, which is materially different from the declared purpose of an operational Gmail skill. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a Gmail operations skill intended to work with Gmail deeply (drafts, labels, forwarding, bulk actions, etc.). The code chunk, however, is a test file, not an operational skill implementation. Its behavior is limited to validating internal logic for Gmail draft-origin classification, header parsing, body extraction/decoding, similarity/diff calculations, and fork/content-loss heuristics. While this is Gmail-related, it is not the declared end-user capability set and does not carry out the described Gmail actions. Therefore the supplied code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for advanced Gmail operations, but the supplied code does not implement or reference Gmail, authentication, messaging, threads, labels, drafts, attachments, or email workflows. Instead, it configures a test runner (Vitest), including an environment variable for file roots and coverage settings. This is a materially different primary purpose and resource scope from the declared Gmail functionality, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/index.js (reported line 43)May include surrounding context.

js
../node_modules/@chrischall/mcp-utils/dist/caller/index.js
import { AsyncLocalStorage as AsyncLocalStorage2 } from "node:async_hooks";
var storage2 = new AsyncLocalStorage2();
function withCallerCapabilities(capabilities, fn) {
  return capabilities ? storage2.run(capabilities, fn) : fn();
}
function currentCallerCapabilities() {
  return storage2.getStore();
}
var ENVELOPE_CAPABILITIES_KEY = "io.modelcontextprotocol/clientCapabilities";
var ELICITATION_MODES = ["form", "url"];
function isRecord(value) {
  return typeof value === "object" && value !== null && !Array.isArray(value);
}
function callerCapabilities(ctx) {
  const envelope = isRecord(ctx) && isRecord(ctx.mcpReq) ? ctx.mcpReq.envelope : void 0;
  if (isRecord(envelope)) {
    const declared = envelope[ENVELOPE_CAPABILITIES_KEY];
    if (isRecord(declared))
      return declared;
  }
  return currentCallerCapabilities();
}
function callerAcceptsFormElicitation(ctx) {
  const capabilities = callerCapabilities(ctx);
  if (!capa

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/index.js (reported line 18139)May include surrounding context.

js
ams);
}
function keyof(schema) {
  const shape = schema._zod.def.shape;
  return _enum2(Object.keys(shape));
}
var ZodObject = /* @__PURE__ */ $constructor("ZodObject", (inst, def) => {
  _ensureDefaultMemoizer();
  $ZodObjectJIT.init(inst, def);
  ZodType.init(inst, def);
  inst._zod.processJSONSchema = (ctx, json2, params) => objectProcessor(inst, ctx, json2, params);
  util_exports.installLazyProp(inst, "shape", (self) => self._zod.def.shape, false);
}, {
  keyof() {
    return _enum2(Object.keys(this._zod.def.shape));
  },
  catchall(catchall) {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall }));
  },
  passthrough() {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall: unknown() }));
  },
  loose() {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall: unknown() }));
  },
  strict() {
    return this.clone(util_exports.mergeDefs(this._zod.def, { catchall: never() }));
  },
  strip() {
    return this.clone(util_exports

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · dist/index.js (reported line 27088)May include surrounding context.

js
function validateAsync3() {
      const ruleErrs = gen.let("ruleErrs", null);
      gen.try(() => assignValid((0, codegen_1._)`await `), (e) => gen.assign(valid, false).if((0, codegen_1._)`${e} instanceof ${it.ValidationError}`, () => gen.assign(ruleErrs, (0, codegen_1._)`${e}.errors`), () => gen.throw(e)));
      return ruleErrs;
    }
    function validateSync() {
      const validateErrs = (0, codegen_1._)`${validateRef}.errors`;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · dist/index.js (reported line 33507)May include surrounding context.

js
if (typeof promptName !== "string") return;
        const prompt = this._registeredPrompts[promptName];
        if (prompt === void 0 || !prompt.enabled) return;
        return prompt.scopeChallenge?.(context);
      }
      default:
        return;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · dist/index.js (reported line 33709)May include surrounding context.

js
if (typeof promptName !== "string") return;
        const prompt = this._registeredPrompts[promptName];
        if (prompt === void 0 || !prompt.enabled) return;
        return prompt.scopeChallenge?.(context);
      }
      default:
        return;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · dist/index.js (reported line 34627)May include surrounding context.

js
return walk(value, keep, drop);
}
function normalizeRules(rules) {
  return rules.map((rule) => typeof rule === "string" ? rule.toLowerCase() : new RegExp(rule.source, rule.flags));
}
function matchesRule(key, rules) {
  const lower = key.toLowerCase();

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as Gmail-only, but the bundled server registers broad Google auth and additional Gmail-adjacent capabilities, including account bootstrap and remote OAuth flows. This creates a dangerous trust-boundary mismatch: operators or upstream policy may allow the skill assuming limited mail operations, while the actual code can initiate wider account and credential workflows.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
77% confidence
Finding

The skill accepts and persists a long-lived Gmail refresh token in a persistent data directory-backed keyring, which materially increases the blast radius if the host, home directory, or keyring password is compromised. Because this connector enables broad Gmail operations, a stolen refresh token could enable durable unauthorized access to email content and account actions.

Content

Scanner excerpt · mint.yaml (reported line 34)May include surrounding context.

yaml
required: false
    help: >-
      Google OAuth refresh token (`gog auth tokens export` prints one). Imported
      into gog's keyring at startup with GOG_CLIENT_ID; stripped from the
      spawned CLI's environment by runner.ts's *_TOKEN rule. Changing it
      re-imports on the next start; an in-connector re-auth
      (gog_auth_add_url/complete) stays in effect until it changes.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 51)May include surrounding context.

yaml
The Google account to act as. Required for the startup auth bootstrap
      (the refresh token is imported under this email); otherwise defaults to
      gog's single/most recent account.
  - name: GOG_KEYRING_BACKEND
    required: false
    help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 61)May include surrounding context.

yaml
The Google account to act as. Required for the startup auth bootstrap
      (the refresh token is imported under this email); otherwise defaults to
      gog's single/most recent account.
  - name: GOG_KEYRING_BACKEND
    required: false
    help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mint.yaml (reported line 55)May include surrounding context.

yaml
required: false
    help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS
      keychain — so the keyring lives on the persistent data dir.
  - name: GOG_KEYRING_PASSWORD
    secret: true
    required: false

Credential Access

High
Category
Privilege Escalation
Confidence
81% confidence
Finding

Allowing a file-backed keyring on a headless host means sensitive Gmail credentials may be stored persistently on disk, which is a meaningful security risk if the host is multi-tenant, weakly permissioned, or backups are exposed. In the context of a high-privilege Gmail automation skill, compromise of that file-backed store could lead to mailbox access, message manipulation, and ongoing re-authenticated sessions.

Content

Scanner excerpt · mint.yaml (reported line 56)May include surrounding context.

yaml
help: >-
      gog's credential store. Set to "file" on a headless host — there is no OS
      keychain — so the keyring lives on the persistent data dir.
  - name: GOG_KEYRING_PASSWORD
    secret: true
    required: false
    help: >-

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

The manifest explicitly states that GOG_KEYRING_PASSWORD is not stripped from the spawned CLI environment, which increases exposure to local process-environment leakage channels such as debug logs, crash reports, or process inspection on weakly isolated systems. While gog may legitimately need the password, keeping a decryption secret in child process environments raises credential-handling risk.

Content

Scanner excerpt · mint.yaml (reported line 60)May include surrounding context.

yaml
secret: true
    required: false
    help: >-
      Encrypts gog's file keyring on the data dir. Required with
      GOG_KEYRING_BACKEND=file. Deliberately not stripped from the spawned
      CLI's environment — it is the one credential gog itself reads.
  - name: GOG_READONLY

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/index.js:35881

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/index.js:27959

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:35025