gemini-image-gen
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands like
lsandmvto find and relocate downloaded images within the user's Downloads directory. This is standard behavior for the tool's intended purpose. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its 'Real-Time Web Search' framework. 1. Ingestion points: External web content enters the context during the processing of search results for image generation. 2. Boundary markers: No explicit delimiters or instructions are provided to mitigate malicious content in search results. 3. Capability inventory: Browser automation and local shell command execution. 4. Sanitization: None.
- [SAFE]: The skill interacts with the official Google Gemini domain and references documentation from the trusted Google Cloud blog. No malicious code, obfuscation, or unauthorized data exfiltration patterns were detected.
Audit Metadata