think
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to construct and execute shell commands by interpolating user-provided text (e.g., [Your problem], [IDEA], [SYMPTOM]) directly into double-quoted strings for the
geminiCLI tool. This pattern is vulnerable to shell command injection if the input contains shell metacharacters such as backticks (`), dollar-parentheses ($()), or semicolons (;). - Evidence: Multiple examples in
SKILL.mdusing the pattern:gemini -m pro -o text -e "" "... [Your problem] ...". - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
google-generativeaipackage from the official Python Package Index (PyPI). This is a trusted source from a well-known organization. - Evidence:
SKILL.mdcontains the commandpip install google-generativeai. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (problems, ideas, code symptoms) and interpolates it into prompts without using boundary markers or sanitization. This allows malicious instructions embedded in the processed data to potentially influence the reasoning output of the Gemini model.
- Ingestion points:
SKILL.mdtemplates forDeep Analysis,Quick Think,Challenge an Idea, andDebugging Strategy. - Boundary markers: Absent; data is placed under simple headers like
PROBLEM:orIDEA:. - Capability inventory: Executes shell commands via the
geminiCLI tool. - Sanitization: None provided in the templates.
Audit Metadata