google-drive-upload
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose matches file upload, but its data flow is weaker than a normal Google Drive integration because it reads a local host config and sends file contents to an arbitrary configured Apps Script URL instead of Google’s official Drive upload API. No malicious payload or installer is present, but the endpoint trust boundary is too loose and could enable unintended file exfiltration if the config is altered or points to a non-Google-controlled service.
Confidence: 88%Severity: 71%
Audit Metadata