gmail

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Gmail automation skill is broadly coherent with its stated purpose and includes reasonable safeguards for destructive actions. The main concerns center on the installer’s trust boundary (local/remote provenance of install.sh), the handling of highly sensitive credentials (OAuth tokens, credentials.json, Anthropic API key), and the potential for misconfiguration during first-run setup. Absent evidence of hardcoded secrets or outbound exfiltration beyond legitimate API calls, the capability set remains plausible for a legitimate developer tool, but the attack surface and credential exposure risk warrant careful supply-chain scrutiny of the installer script, secret storage, and network endpoints. Overall risk: suspicious-to-benign (leaning toward benign with proper controls), securityRisk ~ 0.60, malware ~ 0.20, obfuscated ~ 0.05, confidence ~ 0.62.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:28 AM
Package URL
pkg:socket/skills-sh/wayfind%2Fskills%2Fgmail%2F@c2f3fa689bb1a4f873841965f67eec2384bfdb45