gcloud-log

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent for GCP log analysis and primarily uses official Google CLI flows, but it auto-reads a local cache of accounts/projects, can switch account context, and includes an unnecessary third-party `rtk` command path that could intercept command output. No clear malicious exfiltration is shown, but the extra trust surface and implicit account/project resolution make it higher risk than a minimal read-only logging skill.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
May 7, 2026, 10:36 AM
Package URL
pkg:socket/skills-sh/SainyTK%2Fgcloud-skills%2Fgcloud-log%2F@e95b398e20e4831635cb4a17eca4a1fbef3c1a9c
Security Audit — socket — gcloud-log