gws-setup
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes global installation of the
@googleworkspace/clipackage vianpmto provide the core CLI functionality.\n- [CREDENTIALS_UNSAFE]: Instructions guide the user to save sensitive OAuth client secrets to~/.config/gws/client_secret.jsonto enable API access.\n- [EXTERNAL_DOWNLOADS]: Fetches and installs over 90 agent skills from thegoogleworkspace/clirepository using thenpx skills addcommand.\n- [DATA_EXPOSURE]: The OAuth authentication URL, which contains configuration details and requested scopes, is temporarily stored in/tmp/gws-auth-url.txtto facilitate opening it in a browser when terminal output wraps.
Audit Metadata