antigravity-cli

Fail

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill documents the agy plugin install command, which allows the agent to download and execute code from arbitrary external sources, specifically mentioning support for any GitHub repository and branch. It also describes the automatic resolution and initialization of Git submodules during plugin installation.
  • [METADATA_POISONING]: The skill's description and content claim that the agy CLI is the "official successor to Gemini CLI" from Google. This information is not verifiable and appears to be a deceptive attempt to establish trust for a tool whose actual source is the skill author rather than Google.
  • [PERSISTENCE_MECHANISMS]: Detailed instructions are provided for the agy install command, which automates the modification of shell profiles (such as .bashrc or .zshrc) to persist the tool's configuration and shell aliases across sessions.
  • [PROMPT_INJECTION]: The skill encourages the use of the --dangerously-skip-permissions flag, which instructs the agent to automatically approve all tool permission requests. This effectively bypasses the agent's standard security guardrails and human-in-the-loop safety checks.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by teaching the agent to ingest and process data from a CLI tool that integrates external, untrusted plugins and remote content.
  • Ingestion points: agy command output, remote plugin marketplaces, and third-party GitHub repository content.
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers when processing external data.
  • Capability inventory: The skill provides capabilities for shell command execution (agy), file system modification (agy install), and network access for downloading external code.
  • Sanitization: No methods for sanitizing, validating, or filtering external input are described in the skill.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 14, 2026, 10:19 AM
Security Audit — agent-trust-hub — antigravity-cli