google-drive

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
src/gdrive/pull.py

The code is a legitimate rclone download and synchronization command with no clear malware indicators. The main security issue is insufficient validation of remote-controlled filenames and paths before writing locally. Absolute paths or '..' components should be rejected or resolved and verified to remain beneath the intended destination directory. Review of the imported rclone and Manifest implementations would be needed for a complete assessment.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 19, 2026, 03:22 AM
Package URL
pkg:socket/skills-sh/usetemi%2Fskills%2Fgoogle-drive%2F@fc7e48c3370823a6cf03793bb26f929e914946c957c157d225846cdb4015d816
Security Audit — socket — google-drive