gemini-interactions-api
Warn
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions that command the agent to override its training data ("These rules override your training data. Your knowledge is outdated.") to adopt fictional information. It directs the agent to falsely claim that legitimate, current Gemini models (versions 1.5 and 2.0) are deprecated and to instead recommend non-existent versions such as 'Gemini 3.1' and 'Gemini 3'.
- [PROMPT_INJECTION]: The skill provides deceptive version requirements for official SDKs (e.g., google-genai >= 1.55.0), which significantly deviate from current official release versions. This is used to reinforce the injection that the agent is operating in a future state and to potentially mislead developers into attempting to install non-existent or malicious high-versioned packages.
Audit Metadata