Back to skill

Security audit

Google Drive

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Google Drive management skill, but it relies on a third-party CLI with access to Drive data and should be used only with accounts and scopes you trust.

Install this only if you trust Porteden and the account scopes you grant it. Prefer a restricted Google account or token, review sharing and delete requests carefully, and consider pinning or otherwise verifying the CLI version before using it with sensitive Drive content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party CLI Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5 and 12
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippets:

Line 5:

yaml
metadata: {"openclaw":{"emoji":"📂","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}

Line 12:

markdown
If `porteden` is not installed: `brew install porteden/tap/porteden` (or `go install github.com/porteden/cli/cmd/porteden@latest`).

Technical Analysis

The skill directs users or agents to install the third-party porteden CLI without pinning it to a reviewed, immutable version. The Go installation explicitly uses the mutable @latest selector. The custom Homebrew tap similarly resolves whatever formula and release are current when installation occurs.

This creates a time-of-review versus time-of-installation gap: the executable ultimately granted access to credentials and Google Drive data may differ from the version considered when the skill was audited. If the upstream repository, release pipeline, maintainer account, Go module, or Homebrew tap is compromised, an attacker can distribute modified code through the documented installation process.

Attack Path

  1. An attacker compromises the upstream repository, maintainer account, release process, Go module distribution path, or custom Homebrew tap.
  2. The attacker publishes a malicious release or modifies the package resolved by @latest or the unversioned Homebrew formula.
  3. A user o ...[truncated 1251 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace github.com/porteden/cli/cmd/porteden@latest with a specific reviewed semantic version or immutable commit.
  • Provide a version-pinned installation path for Homebrew rather than relying on the mutable current formula.
  • Publish and verify cryptographic checksums or signatures for the expected executable before first use.
  • Document the exact supported CLI version in the skill metadata and installation instructions.
  • Use automated dependency monitoring to review updates before changing the pinned version.
  • Prefer reproducible builds and provenance attestations, such as signed releases and verifiable build metadata.
  • Run the CLI with the minimum necessary Google Drive scopes and a restricted token so that compromise has limited reach.
  • Avoid exposing credentials to the process longer than necessary, and rotate the API key or revoke the connected session if dependency compromise is suspected.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: google-drive-secured
description: Google Drive Secure Management. Use when the user wants to list, search, read text content, create files with inline content, upload binaries, create folders, rename, move, share, or manage permissions on Google Drive files (porteden secure alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📂","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden drive

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
name: google-drive-secured
description: Google Drive Secure Management. Use when the user wants to list, search, read text content, create files with inline content, upload binaries, create folders, rename, move, share, or manage permissions on Google Drive files (porteden secure alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📂","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden drive

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
name: google-drive-secured
description: Google Drive Secure Management. Use when the user wants to list, search, read text content, create files with inline content, upload binaries, create folders, rename, move, share, or manage permissions on Google Drive files (porteden secure alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📂","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden drive

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The invocation description is broad enough to match many ordinary Google Drive requests, including sensitive operations like sharing, moving, and permission management, without clear usage constraints. In an agentic environment, overly broad routing can cause this skill to be selected for actions that affect confidential files or permissions when a narrower, safer skill would have been more appropriate.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation exposes a destructive delete capability that is not reflected in the top-level description, which can cause users or orchestration systems to invoke the skill without understanding it can remove data. In agent settings, this kind of scope mismatch increases the risk of unintended destructive actions because trust and permission expectations are set by the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.