Back to skill

Security audit

Google Drive Search Files

Security checks for vulnerabilities and agentic risk

Overview

This skill does only Google Drive search, but its command template leaves user search text unsafe to insert into a shell command.

Install only if you trust the local gog CLI setup and ensure agents execute it with an argument-array style call, treating the search query as one literal argument. Avoid using this skill with untrusted or externally supplied search strings until the instruction is tightened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:17
Finding

Shell Command Injection Through Unsanitized Google Drive Search Query

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17-19
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code

markdown
## Cognitive Directives
WHEN [A file or folder needs to be located in Google Drive]
THEN [Execute the native terminal command `gog drive search "query" --json`]

Technical Analysis

The skill directs the agent to insert a search query into a native terminal command. It does not require validation, shell escaping, or execution through an argument-array API.

If an agent replaces the query placeholder with attacker-controlled text and invokes the resulting string through a shell, embedded quotation marks and shell operators can terminate the intended argument and introduce additional commands.

For example, a search query such as:

text
"; id; #

could produce:

sh
gog drive search ""; id; #" --json

When interpreted by a compatible shell, this runs id as a separate command. The exact payload and available operators depend on the operating system and shell used by the agent.

Attack Path

  1. An attacker controls or influences a request that asks the agent to locate a file or folder in Google Drive.
  2. The attacker supplies a crafted search query containing a closing quotation mark and shell control operators.
  3. The agent substitutes that query into the documented gog drive search "query" --json command.
  4. The agent executes the constructed command through a command shell.
  5. The shell interprets the injected operators and executes the attacker's additional command with the privileges of the agent process.

Impact Assessment

Successful exploitation could permit arbitrary local command execution under the account running the agent. The attacker could potentially read files available to that account, access environment variables or locally stored credentials, alter writable files, invoke network utilities, or perform other operations allowed by the agent's o ...[truncated 322 chars]

Remediation
View remediation

Remediation Suggestions

  1. Invoke gog through a process-execution API that accepts an argument array and does not use a shell. Pass the search query as a single argument, conceptually equivalent to:

    text
    ["gog", "drive", "search", user_query, "--json"]
    
  2. Update the skill directive to explicitly prohibit concatenating user input into shell command strings and prohibit shell-enabled execution options.

  3. If shell execution cannot be avoided, apply operating-system-specific shell escaping to the entire query. Generic quote replacement is not sufficient across all supported operating systems.

  4. Validate input according to the expected Google Drive search syntax. Reject control characters and unnecessary shell metacharacters, while treating validation only as defense in depth rather than a substitute for shell-free execution.

  5. Run the command with least privilege, a restricted environment, and no unnecessary access to local credentials or sensitive files.

  6. Add security tests using inputs containing quotation marks, semicolons, command substitutions, pipes, redirection operators, newlines, and platform-specific command separators. Verify that every test value reaches gog as exactly one inert argument.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.