T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Is Installed and Granted Tool Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google Drive skill is coherent and disclosed, but it asks users to trust a third-party hosted service and mutable plugin with broad Drive read/write authority.
Review this before installing if the Google Drive account contains sensitive personal, business, or shared-drive data. Confirm the ClawLink publisher and plugin version, understand what Google OAuth scopes are granted, and be cautious with write, sharing, watch, trash, and permanent-delete operations.
SKILL.md:47Unpinned Third-Party Plugin Is Installed and Granted Tool Access
SKILL.md:17Google Drive OAuth Credentials and File Data Are Entrusted to an External Proxy
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.
| `googledrive_create_folder` | Create a new folder (parent must already exist) | Write |
| `googledrive_upload_file` | Upload a binary file up to 5MB to a folder | Write |
| `googledrive_upload_from_url` | Fetch a file from a URL and upload to Drive server-side | Write |
| `googledrive_resumable_upload` | Start and complete a resumable upload session for large files | Write |
| `googledrive_upload_update_file` | Replace contents of an existing file | Write |
| `googledrive_edit_file` | Overwrite binary file content (not for Google Workspace files) | Write |
No suspicious patterns detected.