gemini

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated Gemini-assistant purpose, but it introduces a non-official wrapper layer (x-cmd) for API key handling and request routing. The same-org installer evidence lowers concern from malicious to medium risk, yet the combination of download-execute install patterns, credential forwarding to wrapper tooling, and broad file/git-diff upload capability makes the trust footprint larger than a minimal Gemini integration.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fgemini%2F@7ac90d763070fa5c04191ea43cf65c0df2383dab
Security Audit — socket — gemini