gcal-skill

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill appears semantically coherent with its described purpose: it manages Google Calendar data across accounts with explicit user confirmation for event creation, uses standard OAuth flows, and interacts with official Google Calendar APIs. The only notable concern is local token storage without explicit protection; otherwise, the design is proportionate and aligns with expected supply-chain patterns for a calendar-management capability. Recommend adding explicit token encryption or restricted file permissions and clarifying token lifecycle handling to further reduce risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/idanbeck%2Fclaude-skills%2Fgcal-skill%2F@7459c27f7ab96c527d39e97856a4f28fcf47427b