gemini-api
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Instructional Knowledge Steering: The skill contains directives to the agent to disregard its existing knowledge regarding model versions, labeling them as 'legacy' and 'outdated' in favor of versions documented in the skill. This technique is used to ensure the agent uses specific API parameters but constitutes a form of prompt steering.
- Safety Policy Testing Patterns: The documentation for safety settings includes examples that instruct the model to 'be as mean as possible' or generate disrespectful content to illustrate how thresholds function. While intended for testing, these patterns provide a template for requesting content that might typically trigger safety filters.
- Dynamic Tool Integration via MCP: The skill demonstrates how to use the Model Context Protocol (MCP) to dynamically fetch and run an external package (
@philschmid/weather-mcp) usingnpx. Executing code from third-party registries at runtime is a potential security consideration. - Sandbox Code Execution Capability: The guide includes usage of a 'Code Execution' tool that enables the model to generate and run Python code. This feature provides powerful dynamic execution capabilities within the model's environment.
- External Data Ingestion Surface: The skill implements tools to process content from URLs, YouTube videos, and Google Cloud Storage. Ingesting untrusted content from these external sources into the prompt context creates a potential surface for indirect prompt injection if the sources contain hidden instructions.
Audit Metadata