antigravity-sdk-java
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides developer guidelines and API references for the Antigravity SDK. All identified dependencies and tools originate from the official author namespace ('io.github.glaforge') or well-known organizations.\n- [COMMAND_EXECUTION]: The documentation describes built-in support for shell command execution and Model Context Protocol (MCP) servers via 'npx'. These are presented with clear security guidance, demonstrating how to wrap them in user-confirmation policies ('Policies.askUser') to prevent unauthorized execution.\n- [CREDENTIALS_UNSAFE]: Guidance is provided for managing 'GEMINI_API_KEY' and Google Cloud credentials. The instructions correctly direct users to official Google configuration tools and environment variables, following standard security practices for secret management.\n- [EXTERNAL_DOWNLOADS]: Mentions Maven dependencies and Node.js packages used for extending agent functionality. These downloads target official registries and trusted repositories, aligning with standard developer workflows.
Audit Metadata