gemini-skill

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent, and direct Google API usage is normal, but the skill explicitly prefers routing Gemini usage through OpenRouter, which changes data flow and credential trust to a third party. No hidden malware behavior or overt credential theft is evident, but the third-party routing and legacy SDK guidance make the skill higher risk than a direct official Gemini integration.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Mar 31, 2026, 02:04 AM
Package URL
pkg:socket/skills-sh/zzafergok%2Fskills%2Fgemini-skill%2F@fc41178867b53de7663c1678c68565084813c2fb
Security Audit — socket — gemini-skill