gemini-cli
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/gemini-tool.mjsuseschild_process.spawnto execute the localgeminiCLI tool. While the use ofspawnis generally safer thanexec, the script passes user-controlled arguments (prompts and working directories) directly to the external binary. - [DATA_EXPOSURE]: The skill implements a caching mechanism in
scripts/gemini-tool.mjsto handle large responses (chunks). This cache is stored inos.tmpdir()/gemini-cli-skill-chunks. On multi-user systems, these temporary files—which may contain sensitive source code or intellectual property extracted by Gemini—could be readable by other users if directory permissions are not strictly enforced. - [INDIRECT_PROMPT_INJECTION]: The skill is specifically designed to ingest local files (using the
@pathsyntax) for analysis by an LLM. This creates a surface for indirect prompt injection, where malicious instructions hidden within project files could be executed by the LLM, potentially leading to misleading analysis or the generation of malicious code edits in 'Change Mode'. - Ingestion points: Project files are read via the
geminiCLI when referenced in prompts (e.g.,@src/main.ts). - Boundary markers: The script uses a
[CHANGEMODE INSTRUCTIONS]block to wrap user prompts, but does not provide explicit delimiters or isolation for the content of the files being analyzed. - Capability inventory: The skill possesses the ability to read files (via
geminiCLI) and write to the local filesystem (via the chunk cache). - Sanitization: No sanitization is performed on the file content before it is passed to the LLM.
Audit Metadata