gmail

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the Gmail purpose is coherent, and the Google OAuth setup is consistent with official Gmail API usage, but the skill’s core capability depends on an unverifiable local CLI that receives OAuth tokens, mailbox contents, and can send email on the user’s behalf. That combination makes the data flow and execution trust disproportionate unless the local script’s provenance is independently verified.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:03 AM
Package URL
pkg:socket/skills-sh/earlyaidopters%2Fclaudeclaw%2Fgmail%2F@4636f07cae6508ab9ebab7fe354877b8f256d3f0