gemini-exec
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the
geminibinary viaspawninscripts/gemini-wrapper.cjs. While the use of an argument array mitigates standard shell injection, the skill lacks validation of the inputs passed to the binary. - [COMMAND_EXECUTION]: The
--outputparameter inscripts/gemini-wrapper.cjsenables writing model responses to any file path accessible to the process. There is no path sanitization or restriction to a designated workspace. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection if utilized to process untrusted external data.
- Ingestion points: External content enters via the
<prompt>argument inSKILL.mdand theargs.promptvariable inscripts/gemini-wrapper.cjs. - Boundary markers: No delimiters or defensive instructions are applied to separate user data from instructions.
- Capability inventory: The skill can execute CLI tools and perform file writes.
- Sanitization: No input validation or path sanitization is performed.
Audit Metadata