googlephotos
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose matches its capabilities, and the CLI source appears to be same-org and documented, so this is not overt malware. However, the integration routes Google Photos access and tokens through ClawLink's hosted intermediary rather than direct Google APIs, and it enables external-account write actions through an npm-executed CLI with locally stored credentials. That makes the footprint broader and riskier than a direct first-party Google Photos integration.
Confidence: 88%Severity: 64%
Audit Metadata