Back to skill

Security audit

Google Drive Share File

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it can change Google Drive sharing permissions with too little user confirmation and has a contradictory example that grants write access.

Review this skill before installing. Only use it when you want an agent to change Google Drive sharing permissions, and require the agent to confirm the exact file or folder, recipient, public-vs-user sharing type, and permission role before running gog. The schema example should be corrected to reader unless write access is explicitly requested.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:18
Finding

Command Injection Through Unquoted Dynamic Parameters

Content
View full analysis
--role reader --type user --email `] ``` ### Technical Analysis The documented command places the dynamic `fileId` and `email` values directly into a terminal command without specifying validation, quoting, or shell-safe argument handling. If an agent executes the generated text through a command shell, shell metacharacters embedded in either value could be interpreted as command syntax rather than as data. For example, a malicious value containing command separators or command substitution syntax could append an unintended command to the legitimate `gog drive share` invocation. The vulnerability is particularly significant because file identifiers and recipient addresses may originate from user-controlled requests. Exploitation depends on the agent substituting attacker-controlled input into the command and invoking it through a shell. The document does not provide safeguards against this behavior. ### Attack Path 1. An attacker asks the agent to share a file and supplies a maliciously crafted file identifier or email argument containing shell syntax. 2. The agent substitutes the supplied value into the documented command without validation or escaping. 3. The agent submits the resulting command to a shell-backed terminal tool. 4. The shell interprets the injected metacharacters. 5. The attacker's appended command executes with the same operating-system privileges and environment access as the agent or `gog` process. ### Impact Assessment Successful exploitation could permit arbitrary local command execution under the account running the agent. Depending on that account's privileges, t ...[truncated 385 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:18
Finding

Schema Example Grants Excessive Google Drive Permissions

Content
View full analysis
--role reader --type user --email `] ## Schema Example ```json { "command": "gog drive share file_id_123 --role writer --type user --email example@gmail.com --json" } ``` ``` ### Technical Analysis The primary directive specifies the read-only `reader` role, but the executable schema example assigns the more privileged `writer` role. This contradiction can cause an agent to follow the concrete example rather than the abstract directive and grant modification privileges when only read access was requested. A writer permission exceeds the legitimate needs of an ordinary file-sharing request. The recipient may gain the ability to modify shared content, subject to Google Drive's resource type, policy, and permission model. The skill contains no requirement to obtain explicit authorization before escalating from reader to writer. ### Attack Path 1. A user requests that a Google Drive file or folder be shared, without explicitly requesting modification access. 2. The agent uses the schema example as the command template. 3. The agent executes `gog drive share` with `--role writer`. 4. Google Drive creates a writer permission for the supplied recipient. 5. The recipient uses the excessive permission to modify accessible shared content. An attacker could also encourage use of the documented example to obtain writer access while presenting the request as ordinary sharing. ### Impact Assessment The recipient may receive unauthorized modification privileges over the selected Google Drive file or folder. Depending on Google Drive policy and the resource type, this could enable co ...[truncated 337 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill enables sharing Google Drive files or folders with other users or publicly without any explicit warning, confirmation, or authorization check. Because sharing changes access control on potentially sensitive content, a broad-use agent could exfiltrate private data or unintentionally expose documents through routine task execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation condition is overly broad: 'when a file or folder needs to be shared' can match many normal-language requests without verifying ownership, sensitivity, recipient trust, or whether public exposure was intended. In an agent setting, this increases the risk of unauthorized or accidental permission changes to Google Drive content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.