conventions-antigravity

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references multiple external URLs for official documentation and research, including official Google developer blogs, the Antigravity project site, and the google/skills GitHub repository. These references are documented neutrally as authoritative sources for the platform conventions.
  • [COMMAND_EXECUTION]: Provides a reference for standard CLI commands used within the described ecosystem, such as npx skills add, gemini extensions install, and various slash commands. These are listed for informational purposes to guide agent behavior when interacting with the Antigravity platform.
  • [INDIRECT_PROMPT_INJECTION]: Identifies potential attack surfaces within the documented platform, such as template argument injection ({{args}}), file inclusion via @ imports in GEMINI.md, and shell command substitution in legacy TOML configurations. The skill notes existing safety measures like argument auto-escaping and import path validation.
  • [DYNAMIC_EXECUTION]: Describes the platform's support for MCP (Model Context Protocol) servers and dynamic shell command execution within specific legacy configuration artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:56 PM
Security Audit — agent-trust-hub — conventions-antigravity