Clear licensing, TypeScript declarations, and release notes support straightforward adoption. The package is backed by an active organization with broad contributor activity and recent releases; its release workflow has wider top-level write permissions than necessary.
94%
Total Score
100
100
100
83
100
Both workflows were analyzed successfully, all 22 action references are pinned, and no audit findings or untrusted checkout/script-injection sinks were detected. One workflow uses top-level write permissions, a mild scope concern without an observed untrusted path to exploit it.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-602867 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @chat-adapter/gchat is vulnerable to Authentication Bypass in versions 4.21.0 - 4.36.0. | 4.21.0 - 4.36.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
chat Version 4.41.1 | — | — |
@googleapis/chat Version ^44.6.0 | — | — |
@chat-adapter/shared Version 4.41.1 | — | — |
@googleapis/workspaceevents Version ^9.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.