google-workspace

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Medium-risk but not malicious. The skill’s capabilities broadly match its Google Workspace purpose and its main data flows go to official Google endpoints, but risk increases because it can hand Google OAuth tokens to the third-party gws CLI and may store tokens with weak local file permissions. User-confirmation rules and same-purpose credential scope keep this from looking malicious, but the credential forwarding and local token handling make it suspicious enough to warrant caution.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Aug 28, 2026, 12:50 PM
Package URL
pkg:socket/skills-sh/tt-a1i%2Fhermes-agent%2Fgoogle-workspace%2F@139e15a8272bfcfd97f940995fbe1c085de0e55065164708e3b68befb4efbadd
Security Audit — socket — google-workspace