T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Executable Installed from a Third-Party Homebrew Tap
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent Google Workspace CLI helper, but it asks users to install an unpinned third-party executable and grant broad Google account access.
Review the gog CLI and its Homebrew tap before installing, grant only the Google services you actually need, avoid unattended mutating commands unless you have checked the target account and document IDs, and be prepared to revoke the OAuth grant if you no longer use it.
SKILL.md:5Unpinned Executable Installed from a Third-Party Homebrew Tap
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Use `gog` for Gmail/Calendar/Drive/Contacts/Sheets/Docs. Requires OAuth setup.
Setup (once)
- `gog auth credentials /path/to/client_secret.json`
- `gog auth add you@gmail.com --services gmail,calendar,drive,contacts,sheets,docs`
- `gog auth list`
No suspicious patterns detected.