google-workspace

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent and the visible data flow appears to target official Google APIs, so this is not strongly indicative of malware. However, the skill combines broad OAuth-backed Workspace access, arbitrary JS execution, and undocumented first-run dependency installation, creating medium security risk and limited install-trust transparency.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:43 PM
Package URL
pkg:socket/skills-sh/mitsuhiko%2Fagent-stuff%2Fgoogle-workspace%2F@287104845862894551aa46a0c318c78262a58cc7