An audit of 2,890 OAuth marketplace apps found 918 with scopes, dead domains, or threat-intel flags reaching beyond their stated function. Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these app... [7778 chars]