google-adk

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Google ADK skill appears coherent with its stated purpose: it describes multi-language agent development with ADC-based authentication, tool integration, and deployment patterns aligned to Google Cloud infrastructure. The footprint shows legitimate package sources, standard authentication flows, and clearly defined design rules that constrain risky behavior. There are no obvious credential harvesting, unauthorized data exfiltration, or supply-chain red flags in the provided material. Overall, the skill is BENIGN with a relatively low securityRisk, provided evaluators verify only official release channels and avoid unverified binaries or password-protected archives in any future extensions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 10:18 PM
Package URL
pkg:socket/skills-sh/benjaminwestern%2Fgoogle-engineer-skills%2Fgoogle-adk%2F@1f15270c373edde06e4e5674104ada1225f1aa84