gws-shared
Warn
Audited by Socket on Aug 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose is coherent for a shared enterprise wrapper, but its actual auth flow depends on an undocumented proxy that maps arbitrary --email values to real OAuth tokens. Official upstream tooling is verifiable, yet the local wrapper/proxy layer and its data routing are intentionally opaque, making this a medium security risk rather than confirmed malware.
Confidence: 84%Severity: 58%
Audit Metadata