google-antigravity-sdk

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a technical guide for an AI development framework. It adheres to security best practices by recommending environment variables for secret management and absolute paths for persistent storage.- [SAFE]: The SDK documentation emphasizes a robust safety policy architecture that defaults to denying high-risk operations, such as shell command execution, ensuring a secure developer experience.- [PROMPT_INJECTION]: The framework supports ingesting untrusted data through file reading, PDF processing, and external skill loading. Combined with capabilities like file writing and command execution, this creates a potential surface for indirect prompt injection. However, the documentation highlights that these risks are mitigated by the SDK's built-in safety policies and confirmation handlers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — google-antigravity-sdk