gemini-files
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The Gemini File API skill is coherently aligned with its stated purpose of uploading and managing files for Gemini models. Data flows from local inputs to official Gemini endpoints and returns cloud storage references and status. Credential handling is a potential risk area and should be governed by secure secret management rather than hard-coded values. No download-execute patterns, unverifiable binaries, or suspicious data exfiltration pathways are evident in the provided material. Overall, the risk is moderate and proportional to a legitimate cloud-based file management capability, with recommended safeguards for credentials and data lifecycle.
Confidence: 98%
Audit Metadata