gogcli

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core `gogcli` capability is aligned with the stated Google Workspace purpose and its distribution looks legitimate, but the skill expands trust to a separate `secrets` CLI for keyring-password retrieval and implicitly relies on external binaries to handle highly sensitive Google auth material. Data flow appears consistent with Google Workspace use, so this is not confirmed malware, but the multi-tool credential path and transitive trust make it a medium-risk skill.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
Sep 23, 2026, 05:04 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fgogcli%2F@8c36e0ebd134e458ec2c8a138e846cdc874d94786ac5e0e4a02a371811ea8653
Security Audit — socket — gogcli