Back to skill

Security audit

Multi-API Data Pipeline to Google Sheets

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a Google Sheets data-sync workflow, with no hidden code or deceptive behavior found.

Before installing, make sure the Google service account only has access to the intended Sheet, use least-privilege API credentials, and clarify where failed-write buffers and logs are stored and when they are deleted, especially if syncing business, financial, or customer data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This is a real safety/transparency issue: the skill writes to a live Google Sheet and explicitly states it may buffer data locally if Google Sheets writes fail, but the user-facing description does not clearly warn about those side effects. That can lead users to authorize or run the skill without understanding that persistent external modifications and temporary local data storage may occur, increasing the risk of unintended data exposure or integrity issues.

Static analysis

No suspicious patterns detected.