gog

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The gog skill is coherently scoped as a Google Workspace CLI wrapper. It uses a standard OAuth-based access flow to Google APIs and relies on a third-party Brew tap for installation. The credential and token handling is typical for API-based tooling but introduces host-stored credentials and tokens that require secure management. Overall, the footprint aligns with a developer tooling purpose, but trust hinges on the reliability of the third-party Brew tap and secure handling of OAuth credentials. Treat as moderately suspicious until provenance of the tap is verified; otherwise, it remains Benign with elevated credential/credential-storage considerations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/Gen-Verse%2FOpenClaw-RL%2Fgog%2F@2c9b7bc934b67d90a276472304b3af7b14122fd6