gws-israeli-business-sheets
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The bookkeeping workflow itself is coherent, but the skill’s central install/auth path is not: it asks the agent to install and authenticate with a CLI package that does not match the official Google-published package name in the cited evidence. Because that package would receive Google OAuth credentials and broad sheet access, the skill has a high supply-chain and credential-forwarding risk even without explicit exfiltration behavior.
Confidence: 89%Severity: 84%
Audit Metadata