invoking-antigravity
Audited by Socket on Jul 30, 2026
1 alert found:
MalwareThis module behaves as an OAuth authorization relay/automation wrapper: it captures and logs an interactive session, extracts a Google OAuth authorization URL from the session output, persists it to disk, and later injects an OAuth authorization code from a local file back into the same PTY session. Even though it performs no direct outbound networking in this snippet, the combination of (a) sensitive OAuth artifact harvesting, (b) code injection with no validation, and (c) full PTY transcript logging to a shared/writable directory is strongly indicative of malicious credential/authorization-material handling or at minimum highly dangerous behavior requiring strict contextual verification of the broader project workflow and the executed child binary (~/.local/bin/agy).