gemini-ask

Warn

Audited by Socket on Jun 19, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but its footprint is riskier than a normal Gemini integration because it repeatedly executes a mutable remote installer and routes user prompts through a third-party daemon/extension tied to the browser session instead of official Gemini APIs. This looks more like elevated supply-chain and intermediary data-flow risk than confirmed malware.

Confidence: 83%Severity: 63%
SecurityMEDIUM
scripts/setup.sh
Audit Metadata
Analyzed At
Jun 19, 2026, 07:15 AM
Package URL
pkg:socket/skills-sh/FinpeakInc%2Ffrevana-skills%2Fgemini-ask%2F@0ae02f78c1e8011d365807abe8273c61e575b23707e00dd263a1f5220269580e
Security Audit — socket — gemini-ask