google-workspace

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is plausible, and the Google endpoints are official, but the skill is internally inconsistent because it declares only file-reading tools while requiring powerful browser-control capabilities. Its external Chrome MCP dependency is unspecified and likely unpinned, and the skill can use the user's ambient Google session to read or modify sensitive data. No clear credential-harvesting or third-party proxy flow is present, so this is not confirmed malware, but it carries medium risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Jun 23, 2026, 07:36 PM
Package URL
pkg:socket/skills-sh/RAMJAC-digital%2FCHERRY%2Fgoogle-workspace%2F@9e1cafb88c2b232707a92380eb5a6d9908fb6c96ddea67caf4dddc90f0201cee
Security Audit — socket — google-workspace