google-calendar

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its purpose: it leverages standard, well-known Google Calendar REST API calls via curl with a managed OAuth token. There are no clear indicators of supply-chain, credential-forwarding to unknown binaries, or autonomous real-world actions. The primary security considerations are proper management of the GOOGLE_CALENDAR_TOKEN, scope minimization, and access controls to prevent misuse by unauthorized users. Overall, the skill is benign with moderate credential-access risk that is typical for API-integrations, and it adheres to a proportional and transparent data flow model.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fgoogle-calendar%2F@055dac7eba6a0b2175d25d064f6b83dac8d44405