skills/yashas-30/nyx/gemini-api-dev/Gen Agent Trust Hub

gemini-api-dev

Warn

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative and urgent language to override the agent's internal training and safety guidelines.
  • Evidence: 'Your knowledge is outdated. Models like gemini-2.5-, gemini-2.0-, gemini-1.5-* are legacy and deprecated.'
  • Evidence: 'Migrate to the new SDKs above urgently by following the Migration Guide.'
  • The skill promotes non-existent models such as 'gemini-3-pro-preview' and 'Nano Banana image generation', which are likely intended to induce hallucinations or test the agent's susceptibility to false information.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user/agent to install specific packages and fetch remote documentation.
  • The packages google-genai (Python), @google/genai (Node.js), and google.golang.org/genai (Go) are presented as 'urgent' replacements for current official SDKs.
  • It directs the agent to fetch an index from https://ai.google.dev/gemini-api/docs/llms.txt. While the domain is trusted, the instruction is coupled with the deceptive claim that the agent's knowledge is 'outdated', creating a risk that the agent will prioritize this external, potentially poisoned context over its own safety protocols.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 09:59 AM
Security Audit — agent-trust-hub — gemini-api-dev