gemini-cli-runtime

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a thin Gemini forwarder, but it delegates nearly all work to an opaque local runtime and defaults to write-capable execution. No direct credential theft or explicit exfiltration is shown, yet the combination of blind delegation, raw stdout passthrough, and default write access creates medium security risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 24, 2026, 08:11 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fgemini-cc%2Fgemini-cli-runtime%2F@5d71354cf070554fa7b4f1a77194eb8edef122ad