google-antigravity-sdk
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a technical guide for an AI development framework. It adheres to security best practices by recommending environment variables for secret management and absolute paths for persistent storage.- [SAFE]: The SDK documentation emphasizes a robust safety policy architecture that defaults to denying high-risk operations, such as shell command execution, ensuring a secure developer experience.- [PROMPT_INJECTION]: The framework supports ingesting untrusted data through file reading, PDF processing, and external skill loading. Combined with capabilities like file writing and command execution, this creates a potential surface for indirect prompt injection. However, the documentation highlights that these risks are mitigated by the SDK's built-in safety policies and confirmation handlers.
Audit Metadata