gws-install

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core gws install/auth flow is mostly coherent and uses the project's documented npm distribution, but the skill directly handles OAuth client secrets, relies on a packaged native CLI, and performs transitive installation of a broad skill bundle through a separate `skills` toolchain. There is no clear exfiltration behavior, yet the additional trust chain and credential forwarding make the footprint broader than a minimal 'quick install' helper.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:04 AM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fgws-install%2F@92df8b34da8d8aac5c141bb35eea123034327601