Back to skill

Security audit

Google Drive File Management

Security checks for vulnerabilities and agentic risk

Overview

This Google Drive skill does what it claims, but its implementation has unsafe command execution and download path handling that could let crafted inputs run local commands or write files outside the intended folder.

Review before installing. This skill should only be used with trusted inputs and a limited Google account until fixed. The publisher should replace shell-based exec calls with execFile or spawn argument arrays, validate Drive IDs, emails, roles, limits, paths, and account names, prevent download path traversal and unintended overwrites, and add explicit confirmations for uploads, downloads, and sharing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/index.js:30
Finding

OS Command Injection in the Primary Google Drive Implementation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/index_corrected.js:22
Finding

OS Command Injection in the Alternate Google Drive Implementation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.js:141
Finding

Download Path Traversal and Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/index_corrected.js:91
Finding

Download Path Traversal in the Alternate Implementation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose emphasizes file management, but the skill also supports sharing files and assigning roles, which changes access control and can expose data to third parties. When a skill can create permissions without clearly foregrounding that behavior, users may invoke it expecting storage actions only and accidentally disclose sensitive files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented purpose emphasizes file management, but the skill also supports sharing files and assigning roles, which changes access control and can expose data to third parties. When a skill can create permissions without clearly foregrounding that behavior, users may invoke it expecting storage actions only and accidentally disclose sensitive files.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Sharing a file with an arbitrary email address grants external access to Google Drive content without an explicit warning or confirmation step. In this context, the action is especially sensitive because it changes access permissions and can cause immediate data exposure to third parties, not just local file handling.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill exposes capabilities that can access environment-derived credentials or configuration for Google Drive operations, but it declares no explicit tool scope or permission boundaries. In an agent setting, undocumented access to env-backed auth increases the risk of unintended data access or exfiltration because users and orchestration layers cannot constrain what the skill is allowed to use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages uploading, downloading, and sharing files with a third-party cloud service but does not warn about data sensitivity, privacy implications, or the risk of overwriting or exposing user content. In a file-management context, omission of these warnings makes accidental transfer of confidential workspace data more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module builds shell command strings from user-controlled inputs such as account, file paths, folder IDs, queries, file IDs, and email addresses, then executes them with exec(..., { shell: true }). This is a classic command-injection risk: crafted input containing shell metacharacters can break out of intended arguments and execute arbitrary commands on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Uploading local files to Google Drive transmits potentially sensitive workspace data off-system without any built-in explicit confirmation or warning. In an agent setting, this can enable unintended exfiltration of local files if a user request is ambiguous or if the skill is invoked through indirect prompt manipulation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The download function writes remote content directly into the local workspace without any confirmation, creating a risk of unreviewed file introduction into trusted local storage. This can overwrite expectations, introduce dangerous scripts or documents, and facilitate follow-on attacks if other tools later process the downloaded file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is limited to file management, but the implementation also modifies Google Drive permissions by sharing files with arbitrary email addresses. This expands the capability from file operations into access-control changes, increasing the risk of unauthorized external disclosure of data if the action is invoked unexpectedly or by prompt manipulation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill accesses Google Drive using configured account credentials and enumerates remote file metadata without any built-in consent prompt, disclosure, or scope limitation visible in this code. In a file-management skill this behavior is expected, but in an agent context it is still security-relevant because it can expose private cloud data to downstream agent actions without making the data access explicit to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The download function writes Drive content directly into the local workspace using a file name derived from remote metadata, without any confirmation, policy check, or user-visible disclosure. In an agent environment, automatically materializing remote files into a trusted workspace can introduce unreviewed content that may later be opened, processed, or executed by other tools, increasing the risk of workspace poisoning and unintended data flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing documentation is written in Spanish, but there is no indication that the skill is region-specific or that users can choose another language. This creates a natural-language locale policy issue because the skill appears to impose a language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Comments, function descriptions, and user-facing error messages are consistently presented in Spanish, with no indication that the user can choose a language or that the locale restriction is intentional. This can violate language/locale policy when a skill imposes one language by default without opt-in.

Content

No source excerpt is available for this finding.