gog
Fail
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The gog skill is coherently scoped as a Google Workspace CLI wrapper. It uses a standard OAuth-based access flow to Google APIs and relies on a third-party Brew tap for installation. The credential and token handling is typical for API-based tooling but introduces host-stored credentials and tokens that require secure management. Overall, the footprint aligns with a developer tooling purpose, but trust hinges on the reliability of the third-party Brew tap and secure handling of OAuth credentials. Treat as moderately suspicious until provenance of the tap is verified; otherwise, it remains Benign with elevated credential/credential-storage considerations.
Confidence: 98%
Audit Metadata