gemini-exec

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary function is to execute the gemini CLI tool. It implements this securely by using child_process.spawn with argument arrays in the scripts/gemini-wrapper.cjs script, which avoids shell command injection vulnerabilities.
  • [DATA_EXFILTRATION]: The wrapper script supports an --output flag that enables writing execution results to a file path provided as an argument. This capability is used for saving tool outputs but allows the skill to write to any file system location accessible to the agent process.
  • [PROMPT_INJECTION]: The skill facilitates passing context and prompts to the Gemini CLI, creating a surface for indirect prompt injection if untrusted data is included in the inputs. The skill documentation mitigates this by recommending human review of all generated code and providing built-in sandbox modes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — gemini-exec