gemini-search

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Unsafe string interpolation in the CLI fallback mechanism. The skill instructs the agent to execute a shell command gemini -p '... "QUERY" ...' where QUERY is directly derived from $ARGUMENTS. If the user input contains single quotes, it can break out of the single-quoted string context in Bash, leading to arbitrary command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it interpolates untrusted external inputs directly into the LLM prompt template without robust boundaries or sanitization.
  • Ingestion points: The $ARGUMENTS variable is captured and mapped to the QUERY parameter in SKILL.md.
  • Boundary markers: The query is wrapped only in standard double quotes ("QUERY"), which can be bypassed if the input contains quotes.
  • Capability inventory: The skill has the ability to execute code via the Gemini MCP tool (mcp__gemini-cli__ask-gemini) and via shell commands in the Bash environment.
  • Sanitization: There is no input sanitization, filtering, or escaping defined before the query is interpolated.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — gemini-search