gws-installer

Fail

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill recommends using sudo on macOS/Linux and running the terminal as Administrator on Windows to perform global npm installations, which involves privilege escalation.
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the @googleworkspace/cli package from the official npm registry.
  • [COMMAND_EXECUTION]: Generates shell commands that interpolate user-provided OAuth Client ID and Secret into environment variables (export and $env:), creating a potential vector for command injection if the input contains malicious shell characters.
  • [COMMAND_EXECUTION]: Automatically configures the local Google Cloud SDK (gcloud) environment to use a specific, hardcoded project ID (favorable-valor-490321-e3).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 17, 2026, 01:13 PM