gdrive-access

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches Google Drive access, but its core operation depends on a locally built, insufficiently verifiable `gdrive` CLI that receives credential references and persists OAuth tokens. That combination is broader and riskier than a direct, official API integration, so the main concern is supply-chain trust and credential forwarding rather than confirmed malicious exfiltration.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fgdrive-access%2F@e8ded3bd1514816fdfada31c57d43a589c9531f4