organize-google-contacts
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
AnomalyAnomalyskill-report.json
LOWAnomalyLOW
skill-report.json
No direct evidence of embedded malware exists in the provided fragment (it is metadata/documentation-level content with no executable logic). The dominant security concerns are (1) supply-chain execution risk introduced by npx-based setup of a community MCP package (version/integrity pinning matters) and (2) privacy/integrity risk inherent in managing sensitive Google Contacts/relationship notes with bulk and potentially destructive operations. Recommend pinning the MCP dependency version with integrity controls, minimizing secret exposure in local configs/logs, and adding strong confirmation/limits for bulk/destructive actions.
Confidence: 62%Severity: 55%
Audit Metadata