skills/jezweb/claude-skills/gws-setup/Gen Agent Trust Hub

gws-setup

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes global installation of the @googleworkspace/cli package via npm to provide the core CLI functionality.\n- [CREDENTIALS_UNSAFE]: Instructions guide the user to save sensitive OAuth client secrets to ~/.config/gws/client_secret.json to enable API access.\n- [EXTERNAL_DOWNLOADS]: Fetches and installs over 90 agent skills from the googleworkspace/cli repository using the npx skills add command.\n- [DATA_EXPOSURE]: The OAuth authentication URL, which contains configuration details and requested scopes, is temporarily stored in /tmp/gws-auth-url.txt to facilitate opening it in a browser when terminal output wraps.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 06:21 AM
Security Audit — agent-trust-hub — gws-setup