Back to skill

Security audit

Google Drive

Security checks for vulnerabilities and agentic risk

Overview

This Google Drive skill is coherent and disclosed, but it asks users to trust a third-party hosted service and mutable plugin with broad Drive read/write authority.

Review this before installing if the Google Drive account contains sensitive personal, business, or shared-drive data. Confirm the ClawLink publisher and plugin version, understand what Google OAuth scopes are granted, and be cautious with write, sharing, watch, trash, and permanent-delete operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Is Installed and Granted Tool Access

Content
View full analysis
Remediation
View remediation

other

Error
Location
SKILL.md:17
Finding

Google Drive OAuth Credentials and File Data Are Entrusted to an External Proxy

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
| `googledrive_create_folder` | Create a new folder (parent must already exist) | Write |
| `googledrive_upload_file` | Upload a binary file up to 5MB to a folder | Write |
| `googledrive_upload_from_url` | Fetch a file from a URL and upload to Drive server-side | Write |
| `googledrive_resumable_upload` | Start and complete a resumable upload session for large files | Write |
| `googledrive_upload_update_file` | Replace contents of an existing file | Write |
| `googledrive_edit_file` | Overwrite binary file content (not for Google Workspace files) | Write |

Static analysis

No suspicious patterns detected.