gemini-exec
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's primary function is to execute the
geminiCLI tool. It implements this securely by usingchild_process.spawnwith argument arrays in thescripts/gemini-wrapper.cjsscript, which avoids shell command injection vulnerabilities. - [DATA_EXFILTRATION]: The wrapper script supports an
--outputflag that enables writing execution results to a file path provided as an argument. This capability is used for saving tool outputs but allows the skill to write to any file system location accessible to the agent process. - [PROMPT_INJECTION]: The skill facilitates passing context and prompts to the Gemini CLI, creating a surface for indirect prompt injection if untrusted data is included in the inputs. The skill documentation mitigates this by recommending human review of all generated code and providing built-in sandbox modes.
Audit Metadata