invoking-antigravity

Fail

Audited by Socket on Jul 30, 2026

1 alert found:

Malware
MalwareHIGH
scripts/agy_auth_broker.py

This module behaves as an OAuth authorization relay/automation wrapper: it captures and logs an interactive session, extracts a Google OAuth authorization URL from the session output, persists it to disk, and later injects an OAuth authorization code from a local file back into the same PTY session. Even though it performs no direct outbound networking in this snippet, the combination of (a) sensitive OAuth artifact harvesting, (b) code injection with no validation, and (c) full PTY transcript logging to a shared/writable directory is strongly indicative of malicious credential/authorization-material handling or at minimum highly dangerous behavior requiring strict contextual verification of the broader project workflow and the executed child binary (~/.local/bin/agy).

Confidence: 70%Severity: 85%
Audit Metadata
Analyzed At
Jul 30, 2026, 08:58 PM
Package URL
pkg:socket/skills-sh/oaustegard%2Fclaude-skills%2Finvoking-antigravity%2F@c918e1bb5429cc492173395c226eca4f4cac4c38996650c193fe12d890c688a1
Security Audit — socket — invoking-antigravity