T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:24- Finding
Installer Retrieves a Mutable Remote Executable and Checksum from the Same Trust Source
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a plausible Google Workspace helper, but it asks users to install and authenticate a broad native CLI with under-scoped API and sharing powers.
Review before installing. Use only with a trusted drivectl release, prefer a pinned and independently verified binary, authenticate with least-privilege OAuth scopes, and require explicit confirmation before any create, update, delete, export, or sharing action, especially dynamic API calls outside Drive, Docs, and Sheets.
scripts/install.sh:24Installer Retrieves a Mutable Remote Executable and Checksum from the Same Trust Source
scripts/install.sh:45Checksum Verification Fails Open When Hashing Utilities Are Unavailable
The skill is presented as a Google Workspace interaction helper, but it also authorizes downloading and installing a binary via a bundled script. That materially expands the trust boundary to remote software acquisition and local executable setup, creating supply-chain and arbitrary code execution risk not disclosed by the stated purpose.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
The user must authenticate before using drivectl. It securely caches tokens locally so this only needs to happen once. If the user hasn't authenticated, guide them to do so:
drivectl auth login --secret-file /path/to/your/client_secret.json
(If operating on a headless system or inside an agent environment without a browser, append the --no-browser-auth flag to print a manual authorization URL that the user can click).
The documentation explicitly expands the skill from Drive/Docs/Sheets into 'almost any Google Workspace API endpoint' through a generic dynamic invocation primitive. That materially increases the reachable capability surface beyond the skill's declared scope, enabling actions against unrelated services such as Gmail or Calendar without purpose limitation, review boundaries, or service-specific safety controls.
This file documents a mechanism for arbitrary Google Workspace API invocation that is not justified by the skill metadata and bypasses the safer, purpose-built subcommands. In an agent setting, a broad generic API caller can be repurposed to access or modify sensitive resources outside user expectations, undermining least privilege and increasing the chance of prompt-driven misuse.
The skill clearly instructs use of shell commands, including authentication and optional installation, but declares no explicit tool scope or permission boundaries. In an agent environment, that omission weakens policy enforcement and can allow command execution beyond what a user would reasonably expect from the manifest.
The skill normalizes cached tokens and broad read/update/create operations without prominently warning that it may access, change, export, or persist sensitive Workspace data. In an agent setting, insufficient disclosure increases the chance of unintended data exposure or modification under the user's credentials.
The manifest describes a narrow Drive/Docs/Sheets use case, but the documentation permits invoking any Google Workspace API endpoint through dynamic discovery. This creates capability drift: an agent following the skill could access or modify resources outside the user's expected scope.
Granting broad arbitrary API invocation is dangerous because it turns a task-specific skill into a general-purpose Google Workspace client. In context, that is more dangerous because the skill also handles authentication and cached tokens, so misuse could affect a wide range of tenant data beyond Drive, Docs, and Sheets.
The documentation presents dynamic calls that can execute state-changing operations across Google Workspace but provides no warning that these requests may create, update, share, or delete resources. In an autonomous or semi-autonomous agent context, lack of side-effect guidance and confirmation requirements raises the risk of unintended destructive or privacy-impacting actions.
The examples demonstrate creating a Google Doc and granting reader access to a file, both of which have real integrity and privacy consequences, yet no cautionary note or confirmation requirement accompanies them. Permission changes are especially sensitive because they can expose private data to unintended recipients if invoked from ambiguous or malicious prompts.
The skill instructs the agent to perform a remote state-changing operation on Google Sheets without an explicit warning, confirmation step, or guidance to verify user intent. In an agent setting, this increases the risk of unintended or overly broad modifications to user data, especially if the sheet ID, range, or value is ambiguous or attacker-influenced.
No suspicious patterns detected.