Back to skill

Security audit

Google Drive Download File

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but its command template leaves user-controlled Drive IDs and output paths under-scoped for safe terminal execution.

Install only if you trust the workflow that supplies the Drive file ID and destination path. The invoking agent should pass gog arguments without a shell, validate the Drive ID, and restrict downloads to an approved directory to avoid command injection or unintended file overwrite risk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:17
Finding

Command Injection Through Unquoted Google Drive Parameters

Content
View full analysis
--out `] ``` ### Technical Analysis The skill directs the agent to construct and execute a terminal command by inserting a Google Drive file ID and a local output path into a shell-command template. Neither dynamic parameter is quoted or validated, and the skill does not require execution through a shell-free argument-array API. If an attacker can influence either `fileId` or `localPath`, shell metacharacters such as command separators, substitutions, or redirection operators could be interpreted by the shell rather than passed to `gog` as literal argument data. This can result in arbitrary command execution. The vulnerability is exploitable when the generated command is passed to a shell. Shell-free process invocation with separately supplied arguments would prevent shell parsing, but the current directive does not impose that requirement. ### Attack Path 1. An attacker provides a malicious Google Drive file ID or requested output path containing shell syntax. 2. The agent inserts the attacker-controlled value into the documented command template. 3. The agent executes the generated command through a terminal shell. 4. The shell interprets the injected metacharacters and executes the attacker's additional command. 5. The injected command runs with the same operating-system privileges and environment access as the agent. For example, an output-path value structured as a legitimate path followed by a shell command separator could cause the intended download command and an attacker-selected command to be executed sequentially. ### Impact Assessment Successful exploitation permits arbitrary co ...[truncated 698 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.