brainstorm
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to install the
google-generativeaiPython package. This is an official library from a well-known service provider and is used according to its intended purpose. - [INDIRECT_PROMPT_INJECTION]: The skill utilizes several ingestion points for untrusted data by using placeholders such as
[topic],[product], and[problem]within prompt templates passed to the Gemini CLI. While this is the primary function of the skill, it represents a surface where user-supplied content could attempt to influence the model's output. The skill provides no explicit boundary markers or sanitization for these inputs.
Audit Metadata