google-drive

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities are coherent, but it routes Google Drive access and user data through ClawLink as a third-party broker rather than direct official Google API access. The npm-delivered CLI is not inherently malicious, yet the intermediary credential/data flow and high-impact Drive actions create meaningful security risk.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fgoogle-drive%2F@0bbe5ca915139b1f1a56697b6cdcde8a953ead82a6e569ad1402c5b9d3da1362
Security Audit — socket — google-drive