Fähigkeiten use-gemini-for-code-analysis
📦

use-gemini-for-code-analysis

Inhaltsrevision r1 Hohes Risiko ⚙️ Externe Befehle

Gemini CLIで大規模コードベースを分析

大規模リポジトリは、ローカルコンテキストだけではすばやく全体像を把握するのが困難です。このスキルは、Claude、Codex、またはClaude CodeがGemini CLIを呼び出し、アーキテクチャ、パターン、実装を分析できるようにします。

Unterstützt: Claude Codex Code(CC)
⚠️ 38 Schlecht

Mit meinem Agent installieren

Kopieren Sie diese Anfrage in Ihren Agent. Sie enthält die maßgebliche Skill-Seite und das Manifest.

Agent-Anfrage
Review the Skillstore skill "use-gemini-for-code-analysis" from https://skillstore.io/skills/727474430-use-gemini-for-code-analysis.md and its manifest at https://skillstore.io/api/skills/727474430-use-gemini-for-code-analysis/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Ihr Agent sollte weiterhin seinen Plan anzeigen und alle von der Sicherheitsrichtlinie verlangten Bestätigungen anfordern.

Agent-lesbare Ressourcen

Verwenden Sie diese Links, wenn ein KI-Agent, Crawler oder Skript sauberen Kontext benötigt, statt die vollständige Seite zu lesen.

Testen

„use-gemini-for-code-analysis“ wird verwendet. リポジトリのアーキテクチャを分析してください。

Erwartetes Ergebnis:

簡潔なレポートで、Gemini CLIの結果に基づく主要モジュール、エントリポイント、データフロー、設計判断を一覧化します。

„use-gemini-for-code-analysis“ wird verwendet. 認証機能を追跡してください。

Erwartetes Ergebnis:

レビュー用に、関連ファイル、リクエストフロー、データベース連携、統合ポイントを示します。

„use-gemini-for-code-analysis“ wird verwendet. パフォーマンスとセキュリティ上の懸念をスキャンしてください。

Erwartetes Ergebnis:

ファイルを変更せずに、潜在的なボトルネック、リスクのあるパターン、フォローアップ確認事項をグループ化して出力します。

Sicherheitsaudit

Hohes Risiko
v8 • 4.7.2026 Versionsbericht öffnen

The skill is a Gemini CLI wrapper that encourages broad repository scans and includes command examples. Several static hits are Markdown false positives, but the documented use still creates external-command and data exposure risk through --all-files, --yolo, and unfiltered output.

1
Gescannte Dateien
70
Analysierte Zeilen
6
Prüfelemente
0
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (3)

Hoch
Repository Data Exposure to External Gemini CLI
The skill directs Bash to run Gemini CLI with --all-files, which can send an entire repository to an external AI service. Private source code and secrets could leave the local environment.
The instructions explicitly combine Bash execution, Gemini CLI, and --all-files examples. This clearly creates a third-party data exposure path for full repositories.
Hoch
Confirmation Bypass Encouraged
The skill suggests --yolo to skip confirmations. This weakens safeguards around external CLI execution, broad file access, and third-party data transfer.
Line 25 directly recommends the confirmation-bypass flag. The parenthetical limit to non-destructive tasks reduces but does not remove the risk.
Mittel
Unfiltered Output Handling
The skill says to return Gemini output directly and without modification. Sensitive file paths, snippets, or secrets found during analysis may be returned without review.
The file explicitly requires complete raw output and no interpretation. This is a plausible leakage path if Gemini reports sensitive repository content.
Elemente der Fähigkeitsprüfung (6)

Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.

Hoch
Ruby/shell backtick execution
- 使用 `--all-files` 进行全代码库分析
The line promotes --all-files for Gemini CLI repository analysis, which can expose every project file to an external tool. The risk is broad file disclosure, not Ruby backtick execution.
Hoch
Ruby/shell backtick execution
- 考虑使用 `--yolo` 跳过确认(仅限非破坏性任务)
The line recommends --yolo to skip confirmations, reducing safeguards around external CLI execution. This is risky when paired with broad repository access.
Hoch
Ruby/shell backtick execution
```bash
This fenced shell example runs gemini with --all-files, so the skill instructs external command execution over the full repository. That can disclose private code to Gemini.
Hoch
Ruby/shell backtick execution
```bash
This fenced shell example invokes gemini --all-files for architecture analysis. It is a real external-command pattern with whole-repository data exposure risk.
Hoch
Ruby/shell backtick execution
```bash
This fenced shell example invokes gemini --all-files for feature tracing. The command can send a full repository to an external analysis service.
Hoch
Ruby/shell backtick execution
```bash
This fenced shell example runs gemini --all-files for quality and security scanning. The command is external and reads the complete repository scope.
Geprüft von: codex Audit-Verlauf anzeigen →
Diesen Bericht teilen & zitieren

Teile den versionierten Bewertungsbericht, das neutrale Badge, die Einbettungskarte und Zitate. Skillstore berichtet Nachweise, ohne zu entscheiden, ob dieser Skill sicher ist.

Versionsbericht öffnen
Sicherheitsbewertung

Berichtslink kopieren

https://skillstore.io/skills/727474430-use-gemini-for-code-analysis/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown-Badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/727474430-use-gemini-for-code-analysis/security.svg)](https://skillstore.io/skills/727474430-use-gemini-for-code-analysis?utm_source=security_passport_badge)

HTML-Badge

<a href="https://skillstore.io/skills/727474430-use-gemini-for-code-analysis?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/727474430-use-gemini-for-code-analysis/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Einbettungskarte

<iframe src="https://skillstore.io/embed/skills/727474430-use-gemini-for-code-analysis.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Wissenschaftliche Zitate (APA · BibTeX · CFF)

APA-Zitat

727474430. (2026). use-gemini-for-code-analysis security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/727474430-use-gemini-for-code-analysis/audits/8

BibTeX-Zitat

@techreport{727474430-727474430-use-gemini-for-code-analysis-2026, author = {727474430}, title = {use-gemini-for-code-analysis security audit report (audit version 8)}, institution = {Skillstore}, year = {2026}, number = {8}, url = {https://skillstore.io/skills/727474430-use-gemini-for-code-analysis/audits/8}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "use-gemini-for-code-analysis security audit report (audit version 8)" version: "unspecified" type: report authors: - name: "727474430" date-released: "2026-07-04" url: "https://skillstore.io/skills/727474430-use-gemini-for-code-analysis/audits/8" identifiers: - type: other value: "skillstore:727474430-use-gemini-for-code-analysis:audit:8" description: "Skillstore immutable audit report identifier"

Skillstore-Score

Warum dieser Score Evidenzvertrauen: Mittel
55
Architektur
85
Wartbarkeit
87
Inhalt
69
Gemeinschaft
91
Spezifikationskonformität

Was Sie erstellen können

不慣れなリポジトリを把握する

より深い作業に入る前に、ディレクトリ、コンポーネント、エントリポイント、データフローの高レベルな全体像を作成します。

機能実装を追跡する

特定のプロダクト機能の背後にあるファイル、連携、データ経路を見つけます。

アーキテクチャと品質をレビューする

大規模コードベース全体にわたる広範なパターン、ボトルネック、セキュリティ上の懸念、設計リスクをGeminiにスキャンさせます。

Diese Prompts ausprobieren

リポジトリを把握する
Gemini CLIを使用してこのリポジトリをマッピングしてください。主要なディレクトリ、コンポーネント、データフロー、エントリポイントを返してください。
パターンを見つける
Gemini CLIを使用して、このパターンが出現する場所を特定してください: [pattern]。例、関連ファイル、想定されるリスクを含めてください。
機能を追跡する
Gemini CLIを使用して[feature]を追跡してください。関係するファイル、制御フロー、データフロー、外部連携を示してください。
アーキテクチャリスクを評価する
Gemini CLIを使用してアーキテクチャリスクをレビューしてください。結合度、パフォーマンスのボトルネック、セキュリティ上の懸念、保守性のトレードオフに焦点を当ててください。

Bewährte Praktiken

  • コードベース全体の分析を使用する前に、リポジトリの範囲を確認し、シークレットを除外してください。
  • 質問が1つの機能またはモジュールを対象にしている場合は、焦点を絞ったプロンプトを使用してください。
  • 推奨事項に基づいて行動したり共有したりする前に、Geminiの結果を確認してください。

Vermeiden

  • 許可なくプライベートリポジトリで広範なスキャンを実行しないでください。
  • 不明確なタスクや書き込み可能なタスクに対して、確認をバイパスするフラグを使用しないでください。
  • ローカルで検証せずに、生のGemini出力を検証済みの事実として扱わないでください。

Häufig gestellte Fragen

このスキルにはGemini CLIが必要ですか?
はい。このスキルが文書化されたワークフローを実行するには、Gemini CLIがインストールされ、認証済みである必要があります。
コードを変更しますか?
文書化されたワークフローは分析のみです。CLIはプロジェクトファイルにアクセスできるため、コマンド実行には引き続き注意が必要です。
プライベートリポジトリを分析できますか?
Geminiとファイルを共有することが許可されている場合に限ります。まずシークレットや機密性の高いコードを除外してください。
Claude CodeやCodexで動作しますか?
はい。このスキルはClaude、Codex、Claude Codeのサポートを明示しています。
どのような分析に最も適していますか?
大規模リポジトリ全体にわたるアーキテクチャマップ、パターン検索、機能追跡、品質レビューに適しています。
Geminiの出力を検証しますか?
いいえ。ユーザーまたは呼び出し元エージェントが確認できるように、生のGemini CLI結果を返します。

Entwicklerdetails

Autor

727474430

Lizenz

MIT

Skillstore-Revision

r1

Versionshinweis

Der Autor hat keine Version angegeben.

Ref.

e9e4712298ed071d92417a41714be123eb8364fa

Aktualität der Wartung

18.7.2026

Nutzung

9 Downloads · 151 Aufrufe

Dateistruktur

📄 SKILL.md

Mehr von 727474430

Alle anzeigen
Alle anzeigen