google-workspace
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core Google API usage is purpose-aligned and mostly routed to official Google endpoints, but the skill has a high security footprint: broad OAuth scopes, direct handling of raw token files, and optional credential forwarding to the separate gws CLI. The sqlite database fallback is also disproportionate. This looks more like an over-privileged, risky integration than confirmed malware.
Confidence: 91%Severity: 78%
Audit Metadata