T09 · Insecure Skill Coding Practices
- Location
src/index.js:30- Finding
OS Command Injection in the Primary Google Drive Implementation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google Drive skill does what it claims, but its implementation has unsafe command execution and download path handling that could let crafted inputs run local commands or write files outside the intended folder.
Review before installing. This skill should only be used with trusted inputs and a limited Google account until fixed. The publisher should replace shell-based exec calls with execFile or spawn argument arrays, validate Drive IDs, emails, roles, limits, paths, and account names, prevent download path traversal and unintended overwrites, and add explicit confirmations for uploads, downloads, and sharing.
src/index.js:30OS Command Injection in the Primary Google Drive Implementation
src/index_corrected.js:22OS Command Injection in the Alternate Google Drive Implementation
src/index.js:141Download Path Traversal and Arbitrary File Overwrite
src/index_corrected.js:91Download Path Traversal in the Alternate Implementation
The documented purpose emphasizes file management, but the skill also supports sharing files and assigning roles, which changes access control and can expose data to third parties. When a skill can create permissions without clearly foregrounding that behavior, users may invoke it expecting storage actions only and accidentally disclose sensitive files.
The documented purpose emphasizes file management, but the skill also supports sharing files and assigning roles, which changes access control and can expose data to third parties. When a skill can create permissions without clearly foregrounding that behavior, users may invoke it expecting storage actions only and accidentally disclose sensitive files.
Sharing a file with an arbitrary email address grants external access to Google Drive content without an explicit warning or confirmation step. In this context, the action is especially sensitive because it changes access permissions and can cause immediate data exposure to third parties, not just local file handling.
The skill exposes capabilities that can access environment-derived credentials or configuration for Google Drive operations, but it declares no explicit tool scope or permission boundaries. In an agent setting, undocumented access to env-backed auth increases the risk of unintended data access or exfiltration because users and orchestration layers cannot constrain what the skill is allowed to use.
The skill encourages uploading, downloading, and sharing files with a third-party cloud service but does not warn about data sensitivity, privacy implications, or the risk of overwriting or exposing user content. In a file-management context, omission of these warnings makes accidental transfer of confidential workspace data more likely.
The module builds shell command strings from user-controlled inputs such as account, file paths, folder IDs, queries, file IDs, and email addresses, then executes them with exec(..., { shell: true }). This is a classic command-injection risk: crafted input containing shell metacharacters can break out of intended arguments and execute arbitrary commands on the host.
Uploading local files to Google Drive transmits potentially sensitive workspace data off-system without any built-in explicit confirmation or warning. In an agent setting, this can enable unintended exfiltration of local files if a user request is ambiguous or if the skill is invoked through indirect prompt manipulation.
The download function writes remote content directly into the local workspace without any confirmation, creating a risk of unreviewed file introduction into trusted local storage. This can overwrite expectations, introduce dangerous scripts or documents, and facilitate follow-on attacks if other tools later process the downloaded file.
The skill description is limited to file management, but the implementation also modifies Google Drive permissions by sharing files with arbitrary email addresses. This expands the capability from file operations into access-control changes, increasing the risk of unauthorized external disclosure of data if the action is invoked unexpectedly or by prompt manipulation.
The skill accesses Google Drive using configured account credentials and enumerates remote file metadata without any built-in consent prompt, disclosure, or scope limitation visible in this code. In a file-management skill this behavior is expected, but in an agent context it is still security-relevant because it can expose private cloud data to downstream agent actions without making the data access explicit to the user.
The download function writes Drive content directly into the local workspace using a file name derived from remote metadata, without any confirmation, policy check, or user-visible disclosure. In an agent environment, automatically materializing remote files into a trusted workspace can introduce unreviewed content that may later be opened, processed, or executed by other tools, increasing the risk of workspace poisoning and unintended data flow.
The user-facing documentation is written in Spanish, but there is no indication that the skill is region-specific or that users can choose another language. This creates a natural-language locale policy issue because the skill appears to impose a language without opt-in or justification.
Comments, function descriptions, and user-facing error messages are consistently presented in Spanish, with no indication that the user can choose a language or that the locale restriction is intentional. This can violate language/locale policy when a skill imposes one language by default without opt-in.