gemini-cli

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill operates by executing the gemini command-line utility. It provides detailed instructions for passing user prompts and project files as arguments to perform auxiliary processing.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the @google/gemini-cli package, which is the official tool from a well-known service provider. All installation and documentation links target official repositories and domains associated with Google and Vercel.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, which is a standard feature for its research and analysis purpose but represents a potential attack surface.
  • Ingestion points: External data enters the context through local file reading (read_file tool and @path syntax), web search results (google_web_search), and remote content fetching (web_fetch).
  • Boundary markers: The current prompt templates do not implement specific structural delimiters or "ignore instructions" markers when interpolating external content.
  • Capability inventory: The skill possesses the ability to execute shell commands (via the gemini tool), read local files, and perform network operations.
  • Sanitization: While the prompt templates do not sanitize incoming data, the skill documentation includes a robust 'Validation Pipeline' in patterns.md, recommending syntax checks, security scans (e.g., for XSS or eval usage), and functional testing for all generated output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:22 PM
Security Audit — agent-trust-hub — gemini-cli