Back to skill

Security audit

Google Sheets Append Row

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it can modify Google Sheets data through a shell-style command without enough safeguards.

Review this skill before installing if it may be used on important spreadsheets. Only use it with explicit spreadsheet IDs and ranges you trust, confirm writes before execution, and prefer agents that pass gog arguments structurally rather than interpolating values into a shell command.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:20
Finding

Potential Command Injection Through Unsafely Constructed CLI Arguments

Content
View full analysis
--values-json '[["..."]]'`] ## Schema Example ```json { "command": "gog sheets append sheet_id_123 \"Tab1!A:C\" --values-json '[[\"Val1\", \"Val2\", \"Val3\"]]' --json" } ``` ``` ### Technical Analysis The skill directs an agent to construct and execute a shell command containing dynamic spreadsheet identifiers, ranges, and row values. It does not require validation of these fields or mandate shell-free process execution with an explicit argument array. The JSON value passed to `--values-json` is enclosed in shell single quotes. If untrusted row data contains an apostrophe, it can terminate the quoted argument. Additional shell metacharacters could then be interpreted by the shell rather than passed to `gog` as data. Even without malicious input, legitimate values containing apostrophes can corrupt the command and cause incorrect writes or execution failures. Exploitability depends on the implementing agent interpolating untrusted values into the documented command and invoking it through a shell. The document does not itself contain an active payload, but its prescribed construction pattern lacks the controls needed to prevent this condition. ### Attack Path 1. An attacker controls or influences a spreadsheet ID, range, or row value supplied to the skill. 2. The attacker places a quote-breaking sequence and shell syntax in that input. 3. The agent serializes or directly interpolates the input into the documented `gog sheets append ... --values-json '...'` command. 4. The agent executes the constructed command through a shell. 5. The single-quoted JSON argument is terminate ...[truncated 857 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs an agent to append rows to a Google Sheet, which is a state-changing operation against external user data, but it provides no warning, confirmation gate, or constraints around when modification is authorized. In an agent setting, this can lead to unintended data corruption, duplicate entries, or writes to the wrong spreadsheet/range if the command is invoked from ambiguous or manipulated context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.