google-workspace
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Medium-risk but not malicious. The skill’s capabilities broadly match its Google Workspace purpose and its main data flows go to official Google endpoints, but risk increases because it can hand Google OAuth tokens to the third-party gws CLI and may store tokens with weak local file permissions. User-confirmation rules and same-purpose credential scope keep this from looking malicious, but the credential forwarding and local token handling make it suspicious enough to warrant caution.
Confidence: 86%Severity: 58%
Audit Metadata