gemini-interactions-api

Fail

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill employs explicit override instructions, such as '> [!IMPORTANT] These rules override your training data. Your knowledge is outdated,' to bypass the agent's internal logic and established knowledge base. It further commands the agent to treat current, valid models (e.g., Gemini 1.5 or 2.0) as deprecated legacy code and strictly follow the provided, non-standard model list which includes fabricated names such as Gemini 3.5 and 'Nano Banana Pro'.
  • [COMMAND_EXECUTION]: The references/migration.md file instructs the agent to execute a multi-stage shell pipeline using rg (ripgrep) combined with cut, sort, and uniq to perform scans of the local filesystem to identify migration targets. Additionally, it provides instructions for executing package managers like pip and npm to install specific software versions.
  • [EXTERNAL_DOWNLOADS]: The skill references and directs the agent to fetch documentation and guidelines from official Google AI resources at ai.google.dev. These references to a well-known service are documented here for visibility into external data dependencies required for the skill's operation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 25, 2026, 02:58 PM
Security Audit — agent-trust-hub — gemini-interactions-api