googlephotos

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches its capabilities, and the CLI source appears to be same-org and documented, so this is not overt malware. However, the integration routes Google Photos access and tokens through ClawLink's hosted intermediary rather than direct Google APIs, and it enables external-account write actions through an npm-executed CLI with locally stored credentials. That makes the footprint broader and riskier than a direct first-party Google Photos integration.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fgooglephotos%2F@902ef4434d494bc0f8bbf3f9fefe65dea086b7b63c6274dd83876c2c0cb1207c
Security Audit — socket — googlephotos