google-docs
Audited by Socket on Sep 15, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The core Google Docs capability is coherent with the stated purpose, and local OAuth plus keyring storage are plausible. The main concern is install trust from a personal publisher and the unclear claim that expired tokens are refreshed using a 'Google cloud function,' which suggests a possible intermediary data path not verified as an official Google endpoint.
The code appears intended to implement Google OAuth authentication with keyring-backed token storage. It contains no clear malware behavior or obfuscated payload. The primary security concern is that refresh tokens are transmitted to a hardcoded third-party cloud function, creating a substantial trust and credential-handling dependency. OAuth redirect/state inconsistencies and apparent syntax/runtime errors also make the implementation unreliable. Review and verify the cloud service before deployment, and avoid using the token-printing command in environments where output may be captured.