gemini-cli

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/gemini-tool.mjs uses child_process.spawn to execute the local gemini CLI tool. While the use of spawn is generally safer than exec, the script passes user-controlled arguments (prompts and working directories) directly to the external binary.
  • [DATA_EXPOSURE]: The skill implements a caching mechanism in scripts/gemini-tool.mjs to handle large responses (chunks). This cache is stored in os.tmpdir()/gemini-cli-skill-chunks. On multi-user systems, these temporary files—which may contain sensitive source code or intellectual property extracted by Gemini—could be readable by other users if directory permissions are not strictly enforced.
  • [INDIRECT_PROMPT_INJECTION]: The skill is specifically designed to ingest local files (using the @path syntax) for analysis by an LLM. This creates a surface for indirect prompt injection, where malicious instructions hidden within project files could be executed by the LLM, potentially leading to misleading analysis or the generation of malicious code edits in 'Change Mode'.
  • Ingestion points: Project files are read via the gemini CLI when referenced in prompts (e.g., @src/main.ts).
  • Boundary markers: The script uses a [CHANGEMODE INSTRUCTIONS] block to wrap user prompts, but does not provide explicit delimiters or isolation for the content of the files being analyzed.
  • Capability inventory: The skill possesses the ability to read files (via gemini CLI) and write to the local filesystem (via the chunk cache).
  • Sanitization: No sanitization is performed on the file content before it is passed to the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 09:11 AM