gemini-antigravity

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation and examples for a sandbox environment, referencing official Google developer domains (ai.google.dev, googleapis.com) and well-known services (GitHub, PyPI).
  • [COMMAND_EXECUTION]: The skill's primary purpose is to provision a Linux environment for executing code and system commands. This functionality is clearly described as an isolated sandbox environment for task execution.
  • [EXTERNAL_DOWNLOADS]: The instructions include examples for cloning repositories from GitHub and interacting with package managers like pip. These involve well-known and trusted services.
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted data through task parameters and external agent files. (1) Ingestion points: --task, --agent-file, --skill flags. (2) Boundary markers: None specified. (3) Capability inventory: Full Ubuntu environment with Python, Node.js, and outbound network access. (4) Sanitization: None mentioned. This behavior is documented and inherent to the skill's purpose as a task-execution engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — gemini-antigravity