Back to skill

Security audit

Google Drive Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned for mounting Google Drive, but it handles long-lived Google credentials and installs a persistent system service in ways that need careful review.

Review this before installing or running it on any machine with sensitive Google Drive data. Prefer rclone's normal OAuth flow or a user-scoped service, avoid --allow-other unless you intend to share the mount locally, require restrictive permissions on credential files, and do not run the setup script with untrusted mount paths or without understanding that it creates boot-time system persistence.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-gdrive-mount.sh:55
Finding

Root-Owned Systemd Unit Injection Through Unvalidated Mount Path

Content
View full analysis
}" ``` ```bash echo "==> Setting up systemd auto-mount at $MOUNT..." mkdir -p "$MOUNT" cat > /etc/systemd/system/rclone-gdrive.service <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-gdrive-mount.sh:14
Finding

OAuth Refresh Token Written to a Predictable Shared Temporary File

Content
View full analysis
Exporting OAuth token from gog..." gog auth tokens export "$EMAIL" --out /tmp/gog_token.json --overwrite # Extract values REFRESH_TOKEN=$(python3 -c "import json; print(json.load(open('/tmp/gog_token.json'))['refresh_token'])") CLIENT_ID=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_id'])") CLIENT_SECRET=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_secret'])") ``` ```bash # Cleanup rm -f /tmp/gog_token.json ``` ### Technical Analysis The script stores a long-lived Google OAuth refresh token at the fixed path `/tmp/gog_token.json`. Shared temporary directories are accessible to multiple local users, and predictable names create opportunities for disclosure, file replacement, and symbolic-link or race-condition attacks depending on how `gog` creates and overwrites the destination. The script does not: - Create the temporary file securely with `mktemp`. - Set a restrictive `umask`. - Verify file ownership or permissions. - Register an exit trap to guarantee cleanup. Because `set -e` terminates the script when many commands fail, any error between token export and the final `rm` leaves the credential file behind. ### Attack Path 1. A user runs the setup script, causing `gog` to export a refresh token to the predictable path. 2. A local attacker monitors, pre-creates, links, or attempts to read that path. 3. If permissions or file-creation behavior permit access, the attacker obtains the refresh token or redirects the write. 4. Alternatively, a later command fails and the script exits before cleanup, leaving the token on disk. 5. A stolen refresh token can be exchanged for access tokens ...[truncated 485 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-gdrive-mount.sh:37
Finding

Persistent Rclone Credential File Created Without Enforced Restrictive Permissions

Content
View full analysis
Writing rclone config..." mkdir -p ~/.config/rclone cat > ~/.config/rclone/rclone.conf <
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/setup-gdrive-mount.sh:63
Finding

Google Drive Mount Exposed to Other Local Users by Default

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (22)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Exporting the keyring password into an environment variable and writing tokens to /tmp exposes highly sensitive authentication material to local process inspection, shell history, insecure temp-file handling, or accidental disclosure. This creates a straightforward path to compromise of the user's Google account data.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

gog already has a valid refresh token. Export it:

bash
export GOG_KEYRING_PASSWORD=<your-password>
gog auth tokens export <email@gmail.com> --out /tmp/gog_token.json --overwrite

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs accessing local credential stores and extracting client credentials and refresh tokens from config files. This is dangerous because it normalizes direct secret harvesting and reuse outside the original tool's protected workflow, increasing the risk of credential theft and long-lived account compromise.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
Extract the refresh_token, client_id, and client_secret from:
- `/tmp/gog_token.json` → refresh_token
- `~/.config/gogcli/credentials.json` → client_id, client_secret

## Step 2: Configure rclone

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The instructions encourage manual token refresh and insertion of access tokens into rclone.conf. Handling bearer and refresh tokens manually in plaintext raises the risk of accidental leakage through terminal logs, files, backups, or shared home directories.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

team_drive =

text

Manually refresh the access token (rclone will auto-refresh thereafter):

```bash
curl -s -X POST https://oauth2.googleapis.com/token \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 7)May include surrounding context.

sh
#
# Prerequisites:
#   - gog CLI authenticated with the Gmail account
#   - GOG_KEYRING_PASSWORD set in environment
#   - rclone installed

set -euo pipefail

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The script reads the OAuth client ID directly from the local gog credential file as part of assembling reusable Drive access. While a client ID alone is less sensitive than a secret, this access pattern is part of bulk credential harvesting behavior and contributes to unauthorized reuse of another tool's OAuth configuration.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 21)May include surrounding context.

sh
# Extract values
REFRESH_TOKEN=$(python3 -c "import json; print(json.load(open('/tmp/gog_token.json'))['refresh_token'])")
CLIENT_ID=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_id'])")
CLIENT_SECRET=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_secret'])")

# Step 2: Get access token

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The script reads the OAuth client secret from ~/.config/gogcli/credentials.json and then uses it to mint tokens and persist Drive access. Client secret extraction from another application's stored credentials is sensitive credential access and materially increases the blast radius if the script or host is compromised.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 22)May include surrounding context.

sh
# Extract values
REFRESH_TOKEN=$(python3 -c "import json; print(json.load(open('/tmp/gog_token.json'))['refresh_token'])")
CLIENT_ID=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_id'])")
CLIENT_SECRET=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_secret'])")

# Step 2: Get access token
echo "==> Refreshing access token..."

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 24)May include surrounding context.

sh
CLIENT_ID=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_id'])")
CLIENT_SECRET=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_secret'])")

# Step 2: Get access token
echo "==> Refreshing access token..."
TOKEN_JSON=$(curl -s -X POST https://oauth2.googleapis.com/token \
  -d "client_id=$CLIENT_ID" \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 25)May include surrounding context.

sh
CLIENT_ID=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_id'])")
CLIENT_SECRET=$(python3 -c "import json; print(json.load(open('$HOME/.config/gogcli/credentials.json'))['client_secret'])")

# Step 2: Get access token
echo "==> Refreshing access token..."
TOKEN_JSON=$(curl -s -X POST https://oauth2.googleapis.com/token \
  -d "client_id=$CLIENT_ID" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 26)May include surrounding context.

sh
# Step 2: Get access token
echo "==> Refreshing access token..."
TOKEN_JSON=$(curl -s -X POST https://oauth2.googleapis.com/token \
  -d "client_id=$CLIENT_ID" \
  -d "client_secret=$CLIENT_SECRET" \
  -d "refresh_token=$REFRESH_TOKEN" \

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script writes both the access token and refresh token in plaintext to ~/.config/rclone/rclone.conf, creating a durable credential store that can be reused to access the user's Drive. This is especially risky because the refresh token enables continued reauthentication and the script does not set restrictive permissions or inform the user of the persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script overwrites a systemd unit under /etc, enables it at boot, and starts it immediately without confirmation. That creates persistence and changes system behavior in a privileged location, which is dangerous in an agent skill because it can survive the session and continuously expose mounted cloud data to the local system.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 78)May include surrounding context.

sh
systemctl start rclone-gdrive

# Cleanup
rm -f /tmp/gog_token.json
echo "✅ Google Drive mounted at $MOUNT (auto-mount on boot enabled)"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs use of shell commands but does not declare any tool scope or permission boundaries. In agent environments, undeclared shell capability increases the chance of unsafe execution, especially because the skill performs credential handling and system configuration changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

These instructions direct the user to export OAuth secrets, extract refresh tokens and client secrets, and place them into files without warning about secret exposure, file permissions, shell history, or temporary-file risk. A stolen refresh token or client secret can allow persistent unauthorized access to the user's Google Drive.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

bash
export GOG_KEYRING_PASSWORD=<your-password>
gog auth tokens export <email@gmail.com> --out /tmp/gog_token.json --overwrite

Extract the refresh_token, client_id, and client_secret from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Manually refresh the access token (rclone will auto-refresh thereafter):

bash
curl -s -X POST https://oauth2.googleapis.com/token \
  -d client_id=<client_id> \
  -d client_secret=<client_secret> \
  -d refresh_token=<refresh_token> \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill recommends a system-wide mount and persistent boot-time service with --allow-other but does not warn that this can expose mounted Drive contents to other local users or broaden access on a multi-user system. Persistence via systemd also increases the blast radius of any credential misuse or misconfiguration.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

Enabling a boot-time systemd service establishes persistent execution and ongoing access to Google Drive using stored credentials. While persistence is legitimate for an automount use case, it becomes security-relevant because it survives reboots and may continue exposing data if the host or account is later compromised.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

bash
systemctl daemon-reload
systemctl enable rclone-gdrive
systemctl start rclone-gdrive

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads highly sensitive OAuth material, including a refresh token and client credentials, and uses them non-interactively without warning, confirmation, or safeguards. In this context that is dangerous because refresh tokens can provide long-lived access to Google Drive data, and the script normalizes direct credential extraction from local stores and temporary files.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 26)May include surrounding context.

sh
# Step 2: Get access token
echo "==> Refreshing access token..."
TOKEN_JSON=$(curl -s -X POST https://oauth2.googleapis.com/token \
  -d "client_id=$CLIENT_ID" \
  -d "client_secret=$CLIENT_SECRET" \
  -d "refresh_token=$REFRESH_TOKEN" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

Writing an rclone config that contains a refresh token establishes durable authenticated access that persists beyond the current session. Although not 'session persistence' in the classic malware sense, it creates ongoing credential-backed access that future processes can reuse without reauthenticating the user.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 35)May include surrounding context.

sh
ACCESS_TOKEN=$(echo "$TOKEN_JSON" | python3 -c "import json,sys; print(json.load(sys.stdin)['access_token'])")
EXPIRY=$(date -u -d "+3600 seconds" +"%Y-%m-%dT%H:%M:%SZ" 2>/dev/null || python3 -c "from datetime import datetime,timedelta; print((datetime.utcnow()+timedelta(hours=1)).strftime('%Y-%m-%dT%H:%M:%SZ'))")

# Step 3: Write rclone config
echo "==> Writing rclone config..."
mkdir -p ~/.config/rclone
cat > ~/.config/rclone/rclone.conf <<EOF

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Enabling the service with systemctl creates persistence across reboots, causing the cloud mount to reappear automatically and extending the lifetime of access to Drive data. In an agent skill, unprompted persistence is dangerous because it changes the system beyond the immediate task and may expose sensitive files to future users or processes.

Content

Scanner excerpt · scripts/setup-gdrive-mount.sh (reported line 74)May include surrounding context.

sh
EOF

systemctl daemon-reload
systemctl enable rclone-gdrive
systemctl start rclone-gdrive

# Cleanup

Static analysis

No suspicious patterns detected.