Back to skill

Security audit

Google Sheets via gog

Security checks for vulnerabilities and agentic risk

Overview

This Google Sheets skill mostly does what it says, but it unnecessarily requires users to store a password-like secret in configuration before the skill can load.

Review this skill before installing. It appears purpose-aligned and does not contain executable payloads, but users should avoid putting real passwords or reusable secrets into ordinary OpenClaw config. Prefer removing the password requirement, using OAuth-only setup, and storing any needed secrets in a proper secret manager or environment reference with clear warnings.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:5
Finding

Unnecessary Plaintext Password Configuration Requirement

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes authentication commands that use a local OAuth client secret file and add an account, but it does not warn users that these steps involve sensitive credentials and account authorization. For markdown files, omission of privacy or security warnings around credential-related behavior is in scope for missing user warnings.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:32