gemini

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Gemini CLI-based skill presents a coherent, purpose-aligned integration: it delegates heavy reasoning tasks to the Gemini CLI, uses standard authentication flows, and relies on official distribution sources. Data flows are centered on prompts to Gemini and responses back to the user, with appropriate user-controlled modes and fallbacks. While credential handling and external CLI dependencies introduce typical risks, they are proportionate to enabling the described functionality. Overall, the footprint is benign-to-suspicious but not malicious, with risk primarily from external dependencies and credential exposure in authentication flows. Treat as SUSPICIOUS if credentials are mishandled; otherwise, BENIGN with medium risk due to external binaries and OAuth usage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 08:18 AM
Package URL
pkg:socket/skills-sh/alpoxdev%2Fhypercore%2Fgemini%2F@72d60a4f04245829477c68c9406e51b282aa6234