files

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s capabilities match its stated Google Drive purpose, but trust and data-flow boundaries are weaker than a direct Google API integration. Main risk comes from routing authenticated Drive operations through an opaque Shift gateway and invoking an undocumented local helper for content uploads; this is suspicious/intermediate risk, not confirmed malware.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:11 AM
Package URL
pkg:socket/skills-sh/tryshift-sh%2Fskills-store%2Ffiles%2F@71e48c3089a0f3168d5212a1b6ce6e41bbc0a5ab
Security Audit — socket — files