Back to skill

Security audit

Google Sheet API

Security checks for vulnerabilities and agentic risk

Overview

This Google Sheets CLI is mostly purpose-aligned, but it can modify or delete spreadsheet data with limited safeguards and has supply-chain and credential-selection risks.

Install only if you are comfortable giving this CLI service-account access to the target spreadsheets. Use a least-privilege service account shared only with intended sheets, prefer explicit credential environment variables over automatic credential-file discovery, review commands before allowing an agent to run clear/deleteSheet/batch operations, and pin dependencies or add a reviewed lockfile before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
package.json:10
Finding

Non-Reproducible Dependency Installation Without a Lockfile

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/sheets-cli.js:11
Finding

Implicit Discovery and Loading of Credential Files from Broad Default Locations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · env_example.md (reported line 6)May include surrounding context.

md
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · env_example.md (reported line 16)May include surrounding context.

md
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · env_example.md (reported line 18)May include surrounding context.

md
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/sheets-cli.js (reported line 13)May include surrounding context.

js
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/sheets-cli.js (reported line 15)May include surrounding context.

js
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/sheets-cli.js (reported line 91)May include surrounding context.

js
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json

# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json

# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The deleteSheet command deletes an entire sheet via deleteSheet: { sheetId } with no confirmation, warning, or explanatory output. Deleting a sheet is an irreversible, safety-critical operation affecting user data, so the lack of disclosure is a meaningful safety gap.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents code that uses environment-provided credentials and network access to Google Sheets, but it declares no explicit tool scope such as permissions or allowed-tools. In an agent environment, that mismatch can cause the skill to run with broader-than-expected capabilities, reducing reviewability and increasing the chance of unintended credential access or external data exfiltration.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
## Best fit
- You need a repeatable CLI for automation tasks.
- You want JSON-in/JSON-out for pipelines.
- You need more than basic read/write (formatting, sheet ops, batch updates).

## Not a fit
- You must use end-user OAuth consent flows (this skill is service-account focused).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents data-write endpoints like values.update, values.append, and structural batchUpdate requests including deleteSheet, but it does not include any caution about user data modification or destructive changes. For markdown files, safety-relevant behaviors that can affect user data should be accompanied by a warning or disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The clear command permanently removes cell contents in the specified range by calling the Sheets API clear endpoint, but the code provides no confirmation prompt, warning message, or other user-facing disclosure before doing so. Because this is a destructive operation that affects user data, the absence of any warning increases the risk of accidental data loss.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a caret range (^140.0.0), which allows installation of newer minor/patch releases that are not fixed or reproducibly audited. This creates supply-chain uncertainty and can inadvertently pull in vulnerable or breaking versions over time, especially for a skill that interacts with external Google APIs and may handle credentials.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"help": "node scripts/sheets-cli.js help"
  },
  "dependencies": {
    "googleapis": "^140.0.0"
  }
}

Unverifiable Dependency: googleapis has 1 known advisory(ies) (GHSA-7543-mr7h-6v86 (Improper Authorization in googleapis)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest references googleapis without pinning an exact version, while the package has a known advisory for improper authorization. Because the allowed version range is not deterministic from the manifest alone, consumers may install an affected release, which is more concerning in a Google Sheets skill that likely uses OAuth tokens or service-account credentials to access and modify spreadsheet data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.