google-workspace

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose—unified Google Workspace management across three accounts with cross-account capabilities—is broadly coherent with the described operations and authentication flow. However, there are notable security considerations: sensitive credentials stored in a local, potentially unencrypted path; explicit per-action consent for cross-account data movements is not described; and no explicit secret management or rotation policy is provided. While no malicious external downloads or unverifiable binaries are present, the footprint is high-_privilege and requires strong per-action authorization, explicit user consent prompts for cross-account actions, and explicit secret management. Overall, the risk profile is MEDIUM: benign in intent but with elevated data-access and credential-exposure concerns that warrant tightening scopes, consent prompts, and secret handling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 11:20 AM
Package URL
pkg:socket/skills-sh/krishagel%2Fgeoffrey%2Fgoogle-workspace%2F@7948fba1eee227dbe7b59deada9dfda5a89d4abe