gemini-cli

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The skill provides documentation for a legitimate developer tool and follows security best practices by recommending environment variables for secret management rather than hardcoding credentials.- [COMMAND_EXECUTION]: The CLI tool supports a built-in run_shell_command tool and allows shell execution within custom slash commands. The documentation highlights these capabilities for automation and provides guidance on the auto-approve flag and trusted folder settings to manage risk.- [EXTERNAL_DOWNLOADS]: Installation instructions point to established and trusted package registries (NPM, Homebrew) and official vendor repositories for extensions.- [REMOTE_CODE_EXECUTION]: The skill explains how to configure MCP servers, which involve running external binaries or scripts (e.g., via node, npx, or python). It correctly identifies the trust configuration field as a security-sensitive setting that should only be used for known-safe servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 08:11 AM