Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets.
An audit by OhAuth, the OAuth research project from identity security company Offroad, covered 2,890 public OAuth app listings, with 1,595 on Google Workspace Marketplace and 1,295 on GitHub Marketplace.
On GitHub, 346 apps hold access to code, 183 reach actions, workflows, and runners, and 107 reach organization settings.
Some of these gaps come from the OAuth scope catalog itself.
AI apps that can write49 AI-powered apps hold broad write access, with a lower-bound install footpr…