gemini-cli
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill operates by executing the
geminicommand-line utility. It provides detailed instructions for passing user prompts and project files as arguments to perform auxiliary processing. - [EXTERNAL_DOWNLOADS]: The skill utilizes the
@google/gemini-clipackage, which is the official tool from a well-known service provider. All installation and documentation links target official repositories and domains associated with Google and Vercel. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, which is a standard feature for its research and analysis purpose but represents a potential attack surface.
- Ingestion points: External data enters the context through local file reading (
read_filetool and@pathsyntax), web search results (google_web_search), and remote content fetching (web_fetch). - Boundary markers: The current prompt templates do not implement specific structural delimiters or "ignore instructions" markers when interpolating external content.
- Capability inventory: The skill possesses the ability to execute shell commands (via the
geminitool), read local files, and perform network operations. - Sanitization: While the prompt templates do not sanitize incoming data, the skill documentation includes a robust 'Validation Pipeline' in
patterns.md, recommending syntax checks, security scans (e.g., for XSS or eval usage), and functional testing for all generated output.
Audit Metadata