T08 · Insecure Dependencies
- Location
package.json:10- Finding
Non-Reproducible Dependency Installation Without a Lockfile
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google Sheets CLI is mostly purpose-aligned, but it can modify or delete spreadsheet data with limited safeguards and has supply-chain and credential-selection risks.
Install only if you are comfortable giving this CLI service-account access to the target spreadsheets. Use a least-privilege service account shared only with intended sheets, prefer explicit credential environment variables over automatic credential-file discovery, review commands before allowing an agent to run clear/deleteSheet/batch operations, and pin dependencies or add a reviewed lockfile before production use.
package.json:10Non-Reproducible Dependency Installation Without a Lockfile
scripts/sheets-cli.js:11Implicit Discovery and Loading of Credential Files from Broad Default Locations
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GOOGLE_SERVICE_ACCOUNT_KEY=/path/to/service-account.json
# Option 2: alternative env var name
# GOOGLE_SHEETS_KEY_FILE=/path/to/credentials.json
# Option 3: standard Google env var
# GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
The deleteSheet command deletes an entire sheet via deleteSheet: { sheetId } with no confirmation, warning, or explanatory output. Deleting a sheet is an irreversible, safety-critical operation affecting user data, so the lack of disclosure is a meaningful safety gap.
The skill documents code that uses environment-provided credentials and network access to Google Sheets, but it declares no explicit tool scope such as permissions or allowed-tools. In an agent environment, that mismatch can cause the skill to run with broader-than-expected capabilities, reducing reviewability and increasing the chance of unintended credential access or external data exfiltration.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Best fit
- You need a repeatable CLI for automation tasks.
- You want JSON-in/JSON-out for pipelines.
- You need more than basic read/write (formatting, sheet ops, batch updates).
## Not a fit
- You must use end-user OAuth consent flows (this skill is service-account focused).
This markdown file documents data-write endpoints like values.update, values.append, and structural batchUpdate requests including deleteSheet, but it does not include any caution about user data modification or destructive changes. For markdown files, safety-relevant behaviors that can affect user data should be accompanied by a warning or disclosure.
The clear command permanently removes cell contents in the specified range by calling the Sheets API clear endpoint, but the code provides no confirmation prompt, warning message, or other user-facing disclosure before doing so. Because this is a destructive operation that affects user data, the absence of any warning increases the risk of accidental data loss.
The dependency is specified with a caret range (^140.0.0), which allows installation of newer minor/patch releases that are not fixed or reproducibly audited. This creates supply-chain uncertainty and can inadvertently pull in vulnerable or breaking versions over time, especially for a skill that interacts with external Google APIs and may handle credentials.
"help": "node scripts/sheets-cli.js help"
},
"dependencies": {
"googleapis": "^140.0.0"
}
}
The manifest references googleapis without pinning an exact version, while the package has a known advisory for improper authorization. Because the allowed version range is not deterministic from the manifest alone, consumers may install an affected release, which is more concerning in a Google Sheets skill that likely uses OAuth tokens or service-account credentials to access and modify spreadsheet data.
No suspicious patterns detected.