google-tasks

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent for Google Tasks management and uses an official-looking npm-distributed vendor CLI, so it is not overtly malicious. However, it routes authentication and task data through Membrane as an intermediary and encourages dynamic action creation, which makes the trust boundary broader than a direct Google Tasks integration and raises medium security risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoogle-tasks%2F@ea72a0b09664588b1e4a6ad88e8d050a7c48a5ba
Security Audit — socket — google-tasks