Back to skill

Security audit

drivectl - your command-line tool for interacting with Google Drive

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plausible Google Workspace helper, but it asks users to install and authenticate a broad native CLI with under-scoped API and sharing powers.

Review before installing. Use only with a trusted drivectl release, prefer a pinned and independently verified binary, authenticate with least-privilege OAuth scopes, and require explicit confirmation before any create, update, delete, export, or sharing action, especially dynamic API calls outside Drive, Docs, and Sheets.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:24
Finding

Installer Retrieves a Mutable Remote Executable and Checksum from the Same Trust Source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:45
Finding

Checksum Verification Fails Open When Hashing Utilities Are Unavailable

Content
View full analysis
expected_checksum.txt; then echo "Error: Could not find checksum for ${FILENAME} in checksums.txt" exit 1 fi if command -v sha256sum >/dev/null 2>&1; then sha256sum -c expected_checksum.txt elif command -v shasum >/dev/null 2>&1; then shasum -a 256 -c expected_checksum.txt else echo "Warning: No sha256sum or shasum command found. Skipping checksum validation." fi cd - > /dev/null echo "Extracting..." tar -xzf "${TMP_DIR}/${FILENAME}" drivectl chmod +x drivectl ``` After printing the warning, execution continues into archive extraction and applies executable permissions to `drivectl`. Integrity validation is therefore optional rather than a mandatory security boundary. In a minimal container, stripped-down agent environment, or manipulated `PATH` where neither hashing command can be found, any archive successfully delivered from the configured URL is accepted. HTTPS reduces ordinary network interception risk but does not replace artifact verification and does not protect against compromised upstream release assets or a compromised trust endpoint. ### Attack Path 1. The installer runs in an environment where neither `sha256sum` nor `shasum` is available through `PATH`. Alternatively, an attacker who can influence the execution environment removes those commands from the effective `PATH`. 2. An attacker compromises or replaces the remotely delivered archive through an upstream release compromise or another delivery-channel compromise. 3. The installer downloads the malicious archive and checksum file. 4. The script finds a filename entry but detects n ...[truncated 1043 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Check required tools before downloading any files and provide explicit installation instructions if a dependency is missing. 3. Verify against a digest pinned within the skill package rather than a checksum obtained from the same release. 4. Verify a cryptographic release signature and pin the expected signing identity or public key. 5. Extract only after every integrity and authenticity check has completed successfully. 6. Use `curl --fail --show-error --location` so failed downloads terminate the script. 7. Consider extracting into a staging directory, validating the resulting file type and expected archive layout, and then atomically moving the verified executable to its destination. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a Google Workspace interaction helper, but it also authorizes downloading and installing a binary via a bundled script. That materially expands the trust boundary to remote software acquisition and local executable setup, creating supply-chain and arbitrary code execution risk not disclosed by the stated purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

The user must authenticate before using drivectl. It securely caches tokens locally so this only needs to happen once. If the user hasn't authenticated, guide them to do so:

bash
drivectl auth login --secret-file /path/to/your/client_secret.json

(If operating on a headless system or inside an agent environment without a browser, append the --no-browser-auth flag to print a manual authorization URL that the user can click).

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly expands the skill from Drive/Docs/Sheets into 'almost any Google Workspace API endpoint' through a generic dynamic invocation primitive. That materially increases the reachable capability surface beyond the skill's declared scope, enabling actions against unrelated services such as Gmail or Calendar without purpose limitation, review boundaries, or service-specific safety controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file documents a mechanism for arbitrary Google Workspace API invocation that is not justified by the skill metadata and bypasses the safer, purpose-built subcommands. In an agent setting, a broad generic API caller can be repurposed to access or modify sensitive resources outside user expectations, undermining least privilege and increasing the chance of prompt-driven misuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs use of shell commands, including authentication and optional installation, but declares no explicit tool scope or permission boundaries. In an agent environment, that omission weakens policy enforcement and can allow command execution beyond what a user would reasonably expect from the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill normalizes cached tokens and broad read/update/create operations without prominently warning that it may access, change, export, or persist sensitive Workspace data. In an agent setting, insufficient disclosure increases the chance of unintended data exposure or modification under the user's credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a narrow Drive/Docs/Sheets use case, but the documentation permits invoking any Google Workspace API endpoint through dynamic discovery. This creates capability drift: an agent following the skill could access or modify resources outside the user's expected scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Granting broad arbitrary API invocation is dangerous because it turns a task-specific skill into a general-purpose Google Workspace client. In context, that is more dangerous because the skill also handles authentication and cached tokens, so misuse could affect a wide range of tenant data beyond Drive, Docs, and Sheets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation presents dynamic calls that can execute state-changing operations across Google Workspace but provides no warning that these requests may create, update, share, or delete resources. In an autonomous or semi-autonomous agent context, lack of side-effect guidance and confirmation requirements raises the risk of unintended destructive or privacy-impacting actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples demonstrate creating a Google Doc and granting reader access to a file, both of which have real integrity and privacy consequences, yet no cautionary note or confirmation requirement accompanies them. Permission changes are especially sensitive because they can expose private data to unintended recipients if invoked from ambiguous or malicious prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to perform a remote state-changing operation on Google Sheets without an explicit warning, confirmation step, or guidance to verify user intent. In an agent setting, this increases the risk of unintended or overly broad modifications to user data, especially if the sheet ID, range, or value is ambiguous or attacker-influenced.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.