google-docs

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Google Docs capability is coherent with the stated purpose, and local OAuth plus keyring storage are plausible. The main concern is install trust from a personal publisher and the unclear claim that expired tokens are refreshed using a 'Google cloud function,' which suggests a possible intermediary data path not verified as an official Google endpoint.

Confidence: 79%Severity: 58%
AnomalyLOW
scripts/auth.py

The code appears intended to implement Google OAuth authentication with keyring-backed token storage. It contains no clear malware behavior or obfuscated payload. The primary security concern is that refresh tokens are transmitted to a hardcoded third-party cloud function, creating a substantial trust and credential-handling dependency. OAuth redirect/state inconsistencies and apparent syntax/runtime errors also make the implementation unreliable. Review and verify the cloud service before deployment, and avoid using the token-printing command in environments where output may be captured.

Confidence: 96%Severity: 67%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:56 PM
Package URL
pkg:socket/skills-sh/sanjay3290%2Fai-skills%2Fgoogle-docs%2F@d53edb88fb6cb3e913d065765e9a163dc2c53095783126b2d5434a6f919bc84a