NYC

google-calendar

Fail

Audited by Snyk on Feb 19, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This skill intentionally routes OAuth authorization through an external cloud function (https://google-workspace-extension.geminicli.com) and posts refresh tokens to that endpoint, which constitutes deliberate credential exfiltration and allows a third party to obtain and reuse the user's OAuth tokens.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 19, 2026, 04:01 PM