gemini-cli
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [SAFE]: The skill provides documentation for a legitimate developer tool and follows security best practices by recommending environment variables for secret management rather than hardcoding credentials.- [COMMAND_EXECUTION]: The CLI tool supports a built-in
run_shell_commandtool and allows shell execution within custom slash commands. The documentation highlights these capabilities for automation and provides guidance on theauto-approveflag and trusted folder settings to manage risk.- [EXTERNAL_DOWNLOADS]: Installation instructions point to established and trusted package registries (NPM, Homebrew) and official vendor repositories for extensions.- [REMOTE_CODE_EXECUTION]: The skill explains how to configure MCP servers, which involve running external binaries or scripts (e.g., via node, npx, or python). It correctly identifies thetrustconfiguration field as a security-sensitive setting that should only be used for known-safe servers.
Audit Metadata