google-workspace-setup

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but its trust model is weak. It asks the agent to install and run a third-party personal MCP bridge with broad Google OAuth access, and the install instructions do not match the cited project’s official docs. No confirmed malware or explicit exfiltration is shown, but the supply-chain and credential-forwarding risks are substantial.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
May 20, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fgoogle-workspace-setup%2F@63b362adab7917382d02115b19935557c54b122c
Security Audit — socket — google-workspace-setup