google-drive-upload

Warn

Audited by Socket on Oct 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are mostly aligned, but it uploads files through a custom Google Apps Script intermediary rather than directly to Google Drive’s official API. That makes the file contents and API key visible to a user-configured endpoint whose ownership and code are not verified by the skill. Risk is medium due to data-flow integrity concerns, not confirmed malware.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Oct 8, 2026, 08:58 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fgoogle-drive-upload%2F@d3d98518ed377f4024569516ea380138b28b74f84c8b338e02d47fd0ecb6f810