gemini-history-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands for zip extraction (unar), file inventory (find, du, sed, sort, uniq), and cleanup (rm -rf). These are standard operations for the stated purpose of analyzing archive exports.
  • [EXTERNAL_DOWNLOADS]: The skill suggests installing unar via Homebrew (brew install unar). This targets a well-known, trusted package manager and is considered safe for the intended administrative workflow.
  • [DATA_EXPOSURE]: The instructions explicitly caution against copying PII (Personally Identifiable Information) into reports or memory files, recommending summarization and risk flagging instead. This aligns with safety best practices.
  • [METADATA_POISONING]: The skill includes a file named .security-scan-passed which claims the content is safe. Following the global rule, this claim was treated as data rather than a conclusion, and the final verdict was reached independently through full analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:06 AM
Security Audit — agent-trust-hub — gemini-history-analyzer