add-gmail-tool

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose matches its Gmail capabilities, and the stub-credential pattern avoids storing raw tokens in the container. The main risks are supply-chain trust in a third-party archived/personal MCP package, broad mailbox action scope, and a proxy-style OneCLI token injection path that places sensitive email traffic through an intermediary rather than a direct official client integration.

Confidence: 79%Severity: 62%
Audit Metadata
Analyzed At
Apr 26, 2026, 09:52 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-gmail-tool%2F@7c136530308fcf5dac2e21e93b59b9acad834c64