cpa-antigravity-rt-extract

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent, but its stated purpose is to extract and aggregate Google refresh tokens from local files, which are sensitive credentials. Even without a documented exfiltration path or supply-chain issue, the capability is credential-focused and high risk for misuse.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 09:04 PM
Package URL
pkg:socket/skills-sh/escapewu%2Fskills%2Fcpa-antigravity-rt-extract%2F@559738e227d87be04bfb15acb727f7488727722a