Back to skill

Security audit

Google Drive Skill

Security checks for vulnerabilities and agentic risk

Overview

This Google Drive skill largely matches its stated purpose, but it needs Review because a download path can overwrite local files and read-only commands may still use full Drive credentials.

Review before installing. Use a tightly scoped service account, prefer an API key for public read-only access, avoid directory downloads from untrusted Drive files unless the filename handling is hardened, and be careful with --public, writer roles, and --permanent --yes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/download_file.py:23
Finding

Remote Drive Filename Can Escape the Destination Directory and Overwrite Local Files

Content
View full analysis
None: # Get filename if dest_path is a directory if os.path.isdir(dest_path): meta = ( drive.files() .get(fileId=file_id, fields="name", supportsAllDrives=True) .execute() ) dest_path = os.path.join(dest_path, meta["name"]) request = drive.files().get_media(fileId=file_id, supportsAllDrives=True) with open(dest_path, "wb") as fh: downloader = MediaIoBaseDownload(fh, request) done = False while not done: status, done = downloader.next_chunk() pct = int(status.progress() * 100) print(f"\rDownloading... {pct}%", end="", flush=True) print(f"\nSaved to: {dest_path}") ``` ### Technical Analysis When the destination supplied through `--dest` is a directory, the script retrieves the file name from Google Drive metadata and passes it directly to `os.path.join`. The resulting path is then opened in `wb` mode without normalization, containment validation, or overwrite protection. The Drive filename is remote data and must therefore be treated as untrusted. A name containing path traversal components can cause the resolved destination to escape the selected download directory. On platforms where an attacker-controlled name is interpreted as an absolute path, `os.path.join` can also discard the intended directory entirely. Opening the resulting path with `open(dest_path, "wb")` creates a new file or truncates an existing file. The script does not check whether the target already exists, whether it is a symbolic link, or whether its resolved path remains under the requested directory. ### Attack Path 1. An attacker creates or controls a Google Drive fil ...[truncated 1558 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/drive_client.py:25
Finding

Read-Only Operations Request Full Google Drive Access

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:64
Finding

Third-Party Python Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 470)May include surrounding context.

md
- Never hardcode API keys or service account credentials in source code. Use environment variables or secret managers.
- Restrict API key to the Drive API scope in the Google Cloud Console.
- Service account credentials (`service_account.json`) must be in `.gitignore`.
- When sharing files, prefer time-limited access tokens over permanent public links where possible.
- `"type": "anyone"` with `"role": "writer"` on a production folder is dangerous — audit permissions regularly.

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README documents commands to make files public and share them with others, but it does not clearly warn that these actions can expose sensitive data to anyone with access or to the internet at large. In a skill specifically designed for Drive CRUD and permission management, omission of an explicit disclosure warning increases the chance of accidental oversharing by users who copy commands verbatim.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes environment-dependent behavior by instructing users to read API keys and service account paths from environment variables, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent setting, undeclared access to environment data can expand the skill's effective privileges and make secret exposure or unauthorized use more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says to use the skill whenever the user wants to interact with a public Google Drive, including listing, reading, creating, updating, or deleting files and folders. This is very broad and lacks explicit trigger phrases, scope constraints, or negative examples beyond a couple of excluded API areas, which increases the chance of unintended invocation for common Drive-related requests.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/delete_file.py (reported line 12)May include surrounding context.

python
# Permanently delete (irreversible):
    python delete_file.py --file-id <FILE_ID> --permanent

    # Skip confirmation prompt:
    python delete_file.py --file-id <FILE_ID> --permanent --yes

Warning:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/delete_file.py (reported line 59)May include surrounding context.

python
# Permanently delete (irreversible):
    python delete_file.py --file-id <FILE_ID> --permanent

    # Skip confirmation prompt:
    python delete_file.py --file-id <FILE_ID> --permanent --yes

Warning:

Static analysis

No suspicious patterns detected.