google-workspace

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes an executable shell script scripts/verify.sh that functions as a local security linter. It scans the repository for hardcoded service account keys, exposed private keys, and overly broad OAuth scopes using standard utilities like grep and awk. This script is intended for developer pre-flight checks and does not perform network operations.
  • [SAFE]: Emphasizes security best practices by advising users to never commit service account keys, recommending secret management tools, and providing instructions for implementing keyless authentication via Application Default Credentials (ADC) or Workload Identity Federation (WIF).
  • [SAFE]: Promotes the principle of least privilege by providing a detailed catalog of narrow OAuth scopes (e.g., gmail.send, drive.file) and explaining the security risks associated with broader scopes like mail.google.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — google-workspace