skills/baekenough/hiddink/gemini-exec/Gen Agent Trust Hub

gemini-exec

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the gemini binary via spawn in scripts/gemini-wrapper.cjs. While the use of an argument array mitigates standard shell injection, the skill lacks validation of the inputs passed to the binary.
  • [COMMAND_EXECUTION]: The --output parameter in scripts/gemini-wrapper.cjs enables writing model responses to any file path accessible to the process. There is no path sanitization or restriction to a designated workspace.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection if utilized to process untrusted external data.
  • Ingestion points: External content enters via the <prompt> argument in SKILL.md and the args.prompt variable in scripts/gemini-wrapper.cjs.
  • Boundary markers: No delimiters or defensive instructions are applied to separate user data from instructions.
  • Capability inventory: The skill can execute CLI tools and perform file writes.
  • Sanitization: No input validation or path sanitization is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:16 PM
Security Audit — agent-trust-hub — gemini-exec