google-drive-upload

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose matches file upload, but its data flow is weaker than expected because uploads go through a configurable Google Apps Script intermediary instead of official Google Drive APIs. The scope is fairly narrow, yet the combination of raw config-file credential access, full file-content POSTs, and proactive upload behavior creates meaningful confidentiality risk.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fgoogle-drive-upload%2F@c78576b7ebdc2a206b7594348138b3dc82dcaec3