recipe-send-team-announcement
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The messaging actions are aligned with the stated purpose, so this is not fundamentally deceptive, but the trust chain depends on third-party prerequisite skills and a non-official `gws` CLI with unpinned install evidence. The main risk is supply-chain trust plus the ability to send external communications on the user's behalf; data flow appears intended toward Google Workspace rather than an obvious exfiltration endpoint.
Confidence: 87%Severity: 61%
Audit Metadata