NYC

google-drive

Warn

Audited by Socket on Feb 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/auth.py

This module implements OAuth token management but contains a suspicious design that sends refresh tokens to a non-Google, third-party endpoint (https://google-workspace-extension.geminicli.com/refreshToken). That behavior presents a realistic risk of credential exfiltration and supply-chain compromise. Aside from that, the code has some inconsistencies/bugs in redirect_uri handling and potentially leaks tokens by printing them. I consider this a medium-to-high security risk unless the external service is verified and trusted.

Confidence: 85%Severity: 70%
Audit Metadata
Analyzed At
Feb 19, 2026, 04:19 PM
Package URL
pkg:socket/skills-sh/sanjay3290%2Fai-skills%2Fgoogle-drive%2F@0824cabf470365e3f18f652165233eec9aee3634