NYC

gmail

Warn

Audited by Socket on Feb 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/auth.py

This module implements an OAuth flow and local token storage. The main security concern is that refresh tokens (and potentially authorization codes) are routed through and posted to an external cloud endpoint (https://google-workspace-extension.geminicli.com). That behavior can lead to token exfiltration to whoever operates that endpoint. There is no obfuscation or use of dynamic code execution. If the external service is trusted and intended, the design is acceptable operationally but still sensitive; otherwise it is a high-risk supply-chain leak. Also note a coding bug (wfile.write() with no argument) that may break successful callback handling.

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
Feb 19, 2026, 04:16 PM
Package URL
pkg:socket/skills-sh/sanjay3290%2Fpostgres-skill%2Fgmail%2F@d8597b8e1044fb04869e4e22a19daf48413d713a