gemini-api-dev

Warn

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses imperative language and warning markers to instruct the AI that its internal knowledge is "outdated" and must be disregarded in favor of the provided (hallucinated) model specifications.
  • [PROMPT_INJECTION]: Deceptive information is provided claiming that current-generation Gemini models (1.5, 2.0) are deprecated and that non-existent "Gemini 3" models should be used instead.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of specific SDKs (google-genai, @google/genai, google.golang.org/genai). While these are official Google libraries, their promotion is paired with significant misinformation about model status.
  • [PROMPT_INJECTION]: The instructions create a potential indirect prompt injection surface by directing the agent to fetch and process external content from the ai.google.dev documentation index (llms.txt) without boundary markers or sanitization.
  • Ingestion points: External documentation URLs and the llms.txt index from ai.google.dev.
  • Boundary markers: None identified in the skill instructions.
  • Capability inventory: API content generation and code execution capabilities provided by the referenced SDKs.
  • Sanitization: No explicit validation or filtering of remote documentation content is mentioned.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 15, 2026, 12:53 PM
Security Audit — agent-trust-hub — gemini-api-dev