Back to skill

Security audit

Google Sheets Agent

Security checks for vulnerabilities and agentic risk

Overview

This Google Sheets skill is mostly coherent, but commands described as read-only actually request write-capable Google Sheets access.

Install only if you are comfortable giving the service account write-capable authorization to spreadsheets it can access. Prefer sharing sheets with Viewer access unless writes are needed, use a dedicated least-privilege service account, and consider fixing the script so read/meta use spreadsheets.readonly before relying on it for sensitive sheets.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/sheets.mjs:47
Finding

Read-Only Commands Request Full Google Sheets Read/Write Access

Content
View full analysis
Remediation
View remediation
({ title: s.properties.title, sheetId: s.properties.sheetId, rowCount: s.properties.gridProperties?.rowCount, colCount: s.properties.gridProperties?.columnCount, })), }; } ``` 3. Use the full Sheets scope only for `appendRows()` and `writeRange()`. 4. Cache tokens by scope instead of using one global token slot. ```js const tokenCache = new Map(); async function getAccessToken(scope) { const cached = tokenCache.get(scope); if (cached && Date.now() < cached.expiresAt - 60000) { return cached.token; } // Create a token for the requested s ...[truncated 456 chars]
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
SHEETS=scripts/sheets.mjs

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
Node.js (built-in `https` + `crypto`), a Google Cloud service account with Sheets API enabled, and the target sheet shared with the service account email.

**How does authentication work?**
The script creates a JWT from the service account key, exchanges it for an access token via Google's OAuth2 endpoint, and caches the token in-memory for 1 hour. Supports 1Password, environment variable, or file-based key loading.

**How much does it cost?**
Google Sheets API is free for standard usage. The service account is free. No paid dependencies.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly relies on sensitive environment/file/1Password-based credential access but does not declare any tool scope or permissions boundary in the skill metadata. In an agent ecosystem, this creates an authorization gap: a user or orchestrator cannot easily tell that the skill expects secret material and may permit broader-than-intended access to local secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.