gemini-history-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands for zip extraction (
unar), file inventory (find,du,sed,sort,uniq), and cleanup (rm -rf). These are standard operations for the stated purpose of analyzing archive exports. - [EXTERNAL_DOWNLOADS]: The skill suggests installing
unarvia Homebrew (brew install unar). This targets a well-known, trusted package manager and is considered safe for the intended administrative workflow. - [DATA_EXPOSURE]: The instructions explicitly caution against copying PII (Personally Identifiable Information) into reports or memory files, recommending summarization and risk flagging instead. This aligns with safety best practices.
- [METADATA_POISONING]: The skill includes a file named
.security-scan-passedwhich claims the content is safe. Following the global rule, this claim was treated as data rather than a conclusion, and the final verdict was reached independently through full analysis.
Audit Metadata