google-workspace
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes an executable shell script
scripts/verify.shthat functions as a local security linter. It scans the repository for hardcoded service account keys, exposed private keys, and overly broad OAuth scopes using standard utilities likegrepandawk. This script is intended for developer pre-flight checks and does not perform network operations. - [SAFE]: Emphasizes security best practices by advising users to never commit service account keys, recommending secret management tools, and providing instructions for implementing keyless authentication via Application Default Credentials (ADC) or Workload Identity Federation (WIF).
- [SAFE]: Promotes the principle of least privilege by providing a detailed catalog of narrow OAuth scopes (e.g.,
gmail.send,drive.file) and explaining the security risks associated with broader scopes likemail.google.com.
Audit Metadata