Versioned security assessment

Report ID: SA-82A7FF5F

6/30/2026, 7:41:39 PM

gemini security assessment v3

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
gemini
Version
v3
Maintainer
softaworks
Coverage
2 Files scanned · 566 Lines analyzed
Policy version
Unavailable

Confirmed finding summary

No confirmed security findings

The completed audit recorded no confirmed security findings. This is not proof that the Skill has no side effects.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

The static analyzer flagged many markdown command examples and weak-crypto patterns. The weak-crypto alerts are false positives, but the skill intentionally instructs agents to run Gemini CLI with broad approval modes and process-management commands. No malicious prompt injection, credential exfiltration, or hidden code execution was found.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

2 Files scanned · 566 Lines analyzed

3 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 3 evidence locations

Filesystem access

May read or write local files.

Observed in 3 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 6 evidence locations

Capability review items (3)
Medium
Automated Gemini CLI Execution With Broad Approval
The skill recommends `--approval-mode yolo` for background and automated tasks. This is legitimate for avoiding hangs, but it can permit the external Gemini CLI to run tools, read workspace content, or apply changes without step-by-step approval.
The command examples and approval-mode table explicitly recommend yolo mode for background use. The risk is contextual rather than malicious because the same files also warn about high-impact flags and permission handling.
Medium
Process Termination Commands in Troubleshooting Guidance
The skill includes `pkill -9` and `kill -9` troubleshooting commands for hung Gemini processes. These commands are useful, but an overly broad pattern or wrong PID can terminate unrelated user processes.
The commands are present as markdown examples and serve a real troubleshooting purpose. The risk depends on whether an agent executes them without user confirmation.
Low
Documentation-Only Command Examples Flagged as Shell Execution
Most external-command findings are inline markdown examples, tables, and fenced shell snippets. They are not executable skill code, but they document commands that an assistant may run after user approval.
The files scanned are markdown skill documentation, not scripts or source files. The examples are still operational guidance, so the signal is not fully dismissible.

Risk findings

Confirmed security concerns are separated from items that still need review.

No confirmed security findings were recorded for this completed audit.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (2)
Low
Weak Cryptography Alerts Are False Positives
No weak cryptographic algorithm usage was found in the reviewed content. The high static alerts appear to match ordinary prose and markdown structure rather than crypto APIs or hashing code.
The cited lines describe Gemini features, error handling, or front matter. I found no evidence of MD5, SHA1, DES, RC4, or other cryptographic implementation in these files.
Low
Hardcoded URLs Are Documentation Links
The network findings are links to public Gemini documentation and model reference pages. They do not transmit data or define runtime network calls.
The URLs appear only in the README resources section. No evidence found that the skill sends local data to those URLs.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable