gemini-image-gen

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands like ls and mv to find and relocate downloaded images within the user's Downloads directory. This is standard behavior for the tool's intended purpose.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its 'Real-Time Web Search' framework. 1. Ingestion points: External web content enters the context during the processing of search results for image generation. 2. Boundary markers: No explicit delimiters or instructions are provided to mitigate malicious content in search results. 3. Capability inventory: Browser automation and local shell command execution. 4. Sanitization: None.
  • [SAFE]: The skill interacts with the official Google Gemini domain and references documentation from the trusted Google Cloud blog. No malicious code, obfuscation, or unauthorized data exfiltration patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 09:27 AM
Security Audit — agent-trust-hub — gemini-image-gen