gws-shared

Warn

Audited by Socket on Aug 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent for a shared enterprise wrapper, but its actual auth flow depends on an undocumented proxy that maps arbitrary --email values to real OAuth tokens. Official upstream tooling is verifiable, yet the local wrapper/proxy layer and its data routing are intentionally opaque, making this a medium security risk rather than confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Aug 5, 2026, 09:11 PM
Package URL
pkg:socket/skills-sh/StreakYC%2Fgoogleworkspacecli%2Fgws-shared%2F@0c6e964c43f1bdc2d60dbee2c90ab1272184bbf426979fbc46c03196081a41be
Security Audit — socket — gws-shared