antigravity-sdk-java

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides developer guidelines and API references for the Antigravity SDK. All identified dependencies and tools originate from the official author namespace ('io.github.glaforge') or well-known organizations.\n- [COMMAND_EXECUTION]: The documentation describes built-in support for shell command execution and Model Context Protocol (MCP) servers via 'npx'. These are presented with clear security guidance, demonstrating how to wrap them in user-confirmation policies ('Policies.askUser') to prevent unauthorized execution.\n- [CREDENTIALS_UNSAFE]: Guidance is provided for managing 'GEMINI_API_KEY' and Google Cloud credentials. The instructions correctly direct users to official Google configuration tools and environment variables, following standard security practices for secret management.\n- [EXTERNAL_DOWNLOADS]: Mentions Maven dependencies and Node.js packages used for extending agent functionality. These downloads target official registries and trusted repositories, aligning with standard developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 03:37 AM
Security Audit — agent-trust-hub — antigravity-sdk-java