google-drive
Warn
Audited by Socket on Oct 9, 2026
1 alert found:
AnomalyAnomalyhandler.ts
LOWAnomalyLOW
handler.ts
No clear malicious behavior is present. The upload and download path containment checks are vulnerable to prefix-based bypasses and should use a directory-boundary-safe containment check (and account for symlinks). This is a security risk if tool callers can control workspace_path.
Confidence: 97%Severity: 58%
Audit Metadata