gws-install

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core gws install/auth flow is mostly coherent and uses the project's documented npm distribution, but the skill directly handles OAuth client secrets, relies on a packaged native CLI, and performs transitive installation of a broad skill bundle through a separate `skills` toolchain. There is no clear exfiltration behavior, yet the additional trust chain and credential forwarding make the footprint broader than a minimal 'quick install' helper.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 01:31 PM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fgws-install%2F@ce58814d1579fa0b33a4536527e248c13f727bf9