gmail
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the Gmail purpose is coherent, and the Google OAuth setup is consistent with official Gmail API usage, but the skill’s core capability depends on an unverifiable local CLI that receives OAuth tokens, mailbox contents, and can send email on the user’s behalf. That combination makes the data flow and execution trust disproportionate unless the local script’s provenance is independently verified.
Confidence: 85%Severity: 84%
Audit Metadata