google-agents-cli-workflow
Audited by Socket on Sep 23, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The skill's purpose and capabilities are broadly coherent for a Google ADK development workflow, and the main CLI dependency is verifiably official. The main concern is install trust: the workflow tells the agent to install additional skills through a third-party npx/skills ecosystem, creating transitive trust and broader execution surface than a simple documentation skill. No clear credential harvesting, exfiltration, stealth, or malicious data routing is present.
The supplied fragment is documentation for a plugin and command-override system. It contains no direct malware or data-theft implementation. However, the described mechanism is inherently security-sensitive because installed extensions execute arbitrary code and can override commands, especially at global scope or when trust prompts are bypassed. Review the actual extension YAML and scripts before installation, prefer project scope, pin immutable commit SHAs, and avoid untrusted --yes installations.