Pa Onboarding
PassAudited by VirusTotal on Apr 2, 2026.
Findings (1)
The skill bundle facilitates the onboarding of a personal assistant with broad access to sensitive data, including Gmail, Google Drive, and Calendar. It explicitly instructs the agent to store a monday.com API token in a plaintext file at `~/.credentials/monday-api-token.txt` (SKILL.md), which is a significant security vulnerability. While these high-privilege capabilities and shell-based credential management (using the `gog` utility) are aligned with the stated purpose, the lack of secure secret handling and the request for extensive OAuth scopes represent a high-risk profile.
