gemini-search
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, and Google Gemini CLI usage is consistent with official docs, but the skill’s preferred path depends on an unrelated third-party MCP bridge installed via unpinned npm/npx. That bridge can receive prompts and potentially Gemini credentials, making the skill’s trust footprint larger than necessary for literature search. The main issue is supply-chain and credential-forwarding risk, not confirmed malware.
Confidence: 91%Severity: 84%
Audit Metadata