gemini

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the actual install and auth instructions are internally inconsistent with Google's official Gemini CLI documentation. The wrong package name plus API-key setup create a meaningful risk of installing or authenticating an unintended package, and MCP/transitive installs further expand trust beyond the skill's narrow purpose.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Apr 16, 2026, 05:31 PM
Package URL
pkg:socket/skills-sh/AlekseiUL%2Fsprut-agent-kit%2Fgemini%2F@48d78c2883f622d342dd3deafbeae5bdddf36538
Security Audit — socket — gemini