google-drive
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalysrc/gdrive/pull.py
LOWAnomalyLOW
src/gdrive/pull.py
The code is a legitimate rclone download and synchronization command with no clear malware indicators. The main security issue is insufficient validation of remote-controlled filenames and paths before writing locally. Absolute paths or '..' components should be rejected or resolved and verified to remain beneath the intended destination directory. Review of the imported rclone and Manifest implementations would be needed for a complete assessment.
Confidence: 97%Severity: 58%
Audit Metadata